PT-2023-4315 · Linux+6 · Linux+6

Ross Lagerwall

·

Publicado

2023-08-08

·

Atualizado

2024-10-11

·

CVE-2023-34319

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux (affected versions not specified)
Description The issue is related to the Linux netback driver, which was modified to handle a frontend splitting a packet in a way that not all headers come in one piece. However, the introduced logic did not account for the extreme case of the entire packet being split into many pieces, yet still being smaller than the area that keeps all possible headers together. This unusual packet would trigger a buffer overrun in the driver. The xenvif get requests() function in the drivers/net/xen-netback/netback.c module is specifically mentioned as being related to the issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-8473
BDU:2023-04650
CVE-2023-34319
DLA-3623-1
DLA-3710-1
DSA-5480-1
DSA-5492-1
LSN-0099-1
MGASA-2023-0250
MGASA-2023-0251
MGASA-2023-0328
MGASA-2023-0331
OESA-2023-1584
OESA-2023-1585
OESA-2023-1586
OESA-2023-1587
OESA-2023-1588
OPENSUSE-SU-2023_3392-1
OPENSUSE-SU-2023_3599-1
OPENSUSE-SU-2023_3599-2
OPENSUSE-SU-2023_3600-1
OPENSUSE-SU-2023_3600-2
OPENSUSE-SU-2023_3656-1
OPENSUSE-SU-2023_3682-1
OPENSUSE-SU-2023_3683-1
OPENSUSE-SU-2023_3683-2
OPENSUSE-SU-2023_3684-1
OPENSUSE-SU-2023_3704-1
OPENSUSE-SU-2023_3704-2
OPENSUSE-SU-2023_3964-1
OPENSUSE-SU-2023_3969-1
OPENSUSE-SU-2023_3971-1
OPENSUSE-SU-2023_3988-1
SUSE-SU-2023:3390-1
SUSE-SU-2023:3392-1
SUSE-SU-2023:3599-1
SUSE-SU-2023:3599-2
SUSE-SU-2023:3600-1
SUSE-SU-2023:3600-2
SUSE-SU-2023:3601-1
SUSE-SU-2023:3656-1
SUSE-SU-2023:3681-1
SUSE-SU-2023:3682-1
SUSE-SU-2023:3684-1
SUSE-SU-2023:3705-1
SUSE-SU-2023:3785-1
SUSE-SU-2023:3964-1
SUSE-SU-2023:3969-1
SUSE-SU-2023:3971-1
SUSE-SU-2023:3988-1
USN-6343-1
USN-6439-1
USN-6439-2
USN-6440-1
USN-6440-2
USN-6440-3
USN-6441-1
USN-6441-2
USN-6441-3
USN-6442-1
USN-6444-1
USN-6444-2
USN-6445-1
USN-6445-2
USN-6446-1
USN-6446-2
USN-6446-3
USN-6466-1

Produtos afetados

Alt Linux
Astra Linux
Linux
Linuxmint
Red Os
Suse
Ubuntu