PT-2022-6143 · Linux+1 · Linux Kernel+1
Tal Lossos
·
Published
2022-08-31
·
Updated
2024-11-17
·
CVE-2023-0122
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions v6.0-rc1 through v6.0-rc3
Description
A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in the
nvmet setup auth() function, allows an attacker to perform a Pre-Auth Denial of Service (DoS) attack on a remote machine.Recommendations
For Linux kernel versions v6.0-rc1 through v6.0-rc3, update to version v6.0-rc4 or later to resolve the issue. As a temporary workaround, consider disabling the
nvmet setup auth() function until a patch is available. Restrict access to the NVMe functionality to minimize the risk of exploitation.Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Suse