PT-2023-1659 · Linux+5 · Linux Kernel+5

Pietro Borrello

·

Publicado

2023-02-04

·

Atualizado

2025-02-24

·

CVE-2023-1076

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description The issue is related to a flaw in the Linux Kernel, specifically with the tun/tap sockets having their socket UID hardcoded to 0 due to a type confusion in their initialization function. This could lead to tun/tap sockets being incorrectly treated in filtering/routing decisions, possibly bypassing network filters. The flaw is also associated with the use of an inappropriate data structure description for reading data from memory in the tap open() function of the TAP virtual network adapter driver.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Type Confusion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01204
CVE-2023-1076
DLA-3404-1
MGASA-2023-0148
MGASA-2023-0149
MGASA-2023-0295
MGASA-2023-0296
OESA-2023-1173
OESA-2023-1174
OESA-2023-1177
OESA-2023-1178
OPENSUSE-SU-2023_2646-1
OPENSUSE-SU-2023_2871-1
OPENSUSE-SU-2024:12779-1
OPENSUSE-SU-2024:13704-1
RHSA-2023:6583
RHSA-2023_6583
SUSE-SU-2023:0779-1
SUSE-SU-2023:1608-1
SUSE-SU-2023:1609-1
SUSE-SU-2023:1710-1
SUSE-SU-2023:1800-1
SUSE-SU-2023:1801-1
SUSE-SU-2023:1803-1
SUSE-SU-2023:1811-1
SUSE-SU-2023:1848-1
SUSE-SU-2023:1894-1
SUSE-SU-2023:2232-1
SUSE-SU-2023:2646-1
SUSE-SU-2023:2809-1
SUSE-SU-2023:2871-1
USN-6033-1
USN-6171-1
USN-6172-1
USN-6185-1
USN-6187-1
USN-6207-1
USN-6222-1
USN-6223-1
USN-6256-1
USN-6385-1

Produtos afetados

Astra Linux
Linux Kernel
Linuxmint
Red Hat
Suse
Ubuntu