PT-2023-1150 · Linux+9 · Linux Kernel+9

Frederick Lawler

·

Published

2023-01-09

·

Updated

2024-04-15

·

CVE-2022-47929

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.6
Description The issue is related to a NULL pointer dereference bug in the traffic control subsystem of the Linux kernel. This bug can be exploited by an unprivileged user to trigger a denial of service, resulting in a system crash. The exploitation is possible via a crafted traffic control configuration set up with commands like tc qdisc and tc class, affecting the qdisc graft function in net/sched/sch api.c.
Recommendations For Linux kernel versions prior to 6.1.6, update to version 6.1.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the tc qdisc and tc class commands to minimize the risk of exploitation. Additionally, limiting access to the traffic control configuration can help mitigate the risk until a patch is applied.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2148
ALSA-2023:2458
ALSA-2023:2736
ALSA-2023:2951
ALT-PU-2023-1064
ALT-PU-2023-1126
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
ALT-PU-2024-4263
ALT-PU-2024-4843
AZL-13050
AZL-13123
BDU:2023-00358
CESA-2023_2736
CESA-2023_2951
CVE-2022-47929
DLA-3349-1
DLA-3403-1
DSA-5324-1
MGASA-2023-0007
MGASA-2023-0008
OPENSUSE-SU-2023_0152-1
OPENSUSE-SU-2023_0394-1
OPENSUSE-SU-2023_0410-1
OPENSUSE-SU-2023_0433-1
OPENSUSE-SU-2023_0488-1
RHSA-2023:2148
RHSA-2023:2458
RHSA-2023:2736
RHSA-2023:2951
RHSA-2023_2148
RHSA-2023_2458
RHSA-2023_2736
RHSA-2023_2951
RHSA-2024:0412
SUSE-SU-2023:0152-1
SUSE-SU-2023:0394-1
SUSE-SU-2023:0406-1
SUSE-SU-2023:0407-1
SUSE-SU-2023:0410-1
SUSE-SU-2023:0420-1
SUSE-SU-2023:0433-1
SUSE-SU-2023:0485-1
SUSE-SU-2023:0488-1
SUSE-SU-2023:0618-1
SUSE-SU-2023:0634-1
SUSE-SU-2023:0779-1
USN-5915-1
USN-5917-1
USN-5924-1
USN-5927-1
USN-5934-1
USN-5939-1
USN-5940-1
USN-5951-1
USN-5975-1
USN-5981-1
USN-5984-1
USN-5991-1
USN-6000-1
USN-6001-1
USN-6009-1
USN-6013-1
USN-6014-1
USN-6024-1
USN-6025-1
USN-6030-1
USN-6040-1
USN-6057-1
USN-6134-1
USN-6247-1
USN-6248-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu