CVE-2023-39197: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information via the DCCP protocol.
Affected products
- Fedoraproject Fedora: version 38 only
- Linux Linux Kernel: from 2.6.26, before 5.4.251 (fixed in 5.4.251); from 5.5, before 5.10.188 (fixed in 5.10.188); from 5.11, before 5.15.121 (fixed in 5.15.121); from 5.16, before 6.1.39 (fixed in 6.1.39); from 6.2, before 6.3.13 (fixed in 6.3.13); from 6.4, before 6.4.4 (fixed in 6.4.4)
Published 2024-01-23. Last modified 2026-06-17.