CVE-2023-52880
In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc Any unprivileged user can attach N_GSM0710 ldisc, but it requires CAP_NET_ADMIN to create a GSM network anyway.
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc Any unprivileged user can attach N_GSM0710 ldisc, but it requires CAP_NET_ADMIN to create a GSM network anyway. Require initial namespace CAP_NET_ADMIN to do that.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.24% probability · 16th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/2b85977977cbd120591b23c2450e90a5806a7167Patch
- https://git.kernel.org/stable/c/2d154a54c58f9c8375bfbea9f7e51ba3bfb2e43aPatch
- https://git.kernel.org/stable/c/67c37756898a5a6b2941a13ae7260c89b54e0d88Patch
- https://git.kernel.org/stable/c/7a529c9023a197ab3bf09bb95df32a3813f7ba58Patch
- https://git.kernel.org/stable/c/7d303dee473ba3529d75b63491e9963342107bedPatch
- https://git.kernel.org/stable/c/ada28eb4b9561aab93942f3224a2e41d76fe57faPatch
- https://git.kernel.org/stable/c/2b85977977cbd120591b23c2450e90a5806a7167Patch
- https://git.kernel.org/stable/c/2d154a54c58f9c8375bfbea9f7e51ba3bfb2e43aPatch
- https://git.kernel.org/stable/c/67c37756898a5a6b2941a13ae7260c89b54e0d88Patch
- https://git.kernel.org/stable/c/7a529c9023a197ab3bf09bb95df32a3813f7ba58Patch
- https://git.kernel.org/stable/c/7d303dee473ba3529d75b63491e9963342107bedPatch
- https://git.kernel.org/stable/c/ada28eb4b9561aab93942f3224a2e41d76fe57faPatch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlMailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.