CVE-2023-2248: High severity Microsoft cm1 kernel 5.10.179.1-1 vulnerability
REJECT This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was the duplicate of CVE-2023-31436.
Other sources
Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by a heap-based out-of-bounds read/write flaw in the qfqchangeclass function in the traffic control (QoS) subsystem. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
— IBM
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was the duplicate of CVE-2023-31436.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2248?
CVE-2023-2248 has been rejected and does not have a severity rating as it is a duplicate of CVE-2023-31436.
How do I fix CVE-2023-2248?
Since CVE-2023-2248 has been rejected, no specific fixes or mitigations are necessary for this vulnerability.
What types of systems are affected by CVE-2023-2248?
CVE-2023-2248 is associated with the Linux Kernel but is not applicable due to its rejection.
Who reported CVE-2023-2248?
The details regarding the reporting of CVE-2023-2248 are not specified, as it has been determined to be a duplicate.
What should I do if I implemented protections against CVE-2023-2248?
Since CVE-2023-2248 is a duplicate and has been rejected, reassessing your implementation in relation to CVE-2023-31436 is advisable.