Vulnerabilities > CVE-2022-2663 - Improper Restriction of Communication Channel to Intended Endpoints vulnerability in multiple products

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
linux
debian
CWE-923

Summary

An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured.

Vulnerable Configurations

Part Description Count
OS
Linux
1
OS
Debian
2