CVE-2023-22024: Medium severity oracle vm server vulnerability
In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDSCONNRESET and RDS6CONNRESET, that are not re-entrant. A malicious local user with CAPNETADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22024?
CVE-2023-22024 is a vulnerability in the Unbreakable Enterprise Kernel (UEK) that allows a malicious local user to crash the kernel.
How does CVE-2023-22024 impact Oracle VM Server?
CVE-2023-22024 affects Oracle VM Server version 3.0, allowing a malicious local user to crash the kernel.
Which versions of Oracle Linux are affected by CVE-2023-22024?
CVE-2023-22024 affects Oracle Linux versions 6, 7, 8, and 9.
What is the severity of CVE-2023-22024?
The severity of CVE-2023-22024 is medium with a CVSS 3.1 Base Score of 5.5 (Availability impacts).
Is there a fix available for CVE-2023-22024?
Currently, no fix is available for CVE-2023-22024. It is recommended to stay updated with the latest patches and security advisories from Oracle.