linux-aws-hwe, linux-azure, linux-gcp, linux-gcp-4.15, linux-oracle, linux-raspi2 vulnerability
It was discovered that the IPsec implementation in the Linux kernel did not properly allocate enough memory when performing ESP transformations, leading to a heap-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
02 / AFFECTED SOFTWARE
Affected packages
34 explicit affected versions
59 explicit affected versions
77 explicit affected versions
66 explicit affected versions
58 explicit affected versions
89 explicit affected versions
81 explicit affected versions
57 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
It was discovered that the IPsec implementation in the Linux kernel did not properly allocate enough memory when performing ESP transformations, leading to a heap-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
05 / REFERENCES