A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.
| Version | Score | Severity | Vector String |
|---|---|---|---|
| 3.1 | 3.2 | Low | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N |
| Product | Vendor | Version |
|---|---|---|
| Red Hat Enterprise Linux 8 | Red Hat | <= 6.1.* |
| Red Hat Enterprise Linux 9 | Red Hat | <= 6.2.* |
| Red Hat Enterprise Linux 9 | Red Hat | <= * |
| Red Hat Enterprise Linux 6 | Red Hat | < 0.24.4 |
| Red Hat Enterprise Linux 8 | Red Hat | <= 5.15.* |