PT-2023-1659 · Linux+5 · Linux Kernel+5

Pietro Borrello

·

Published

2023-02-04

·

Updated

2025-02-24

·

CVE-2023-1076

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description The issue is related to a flaw in the Linux Kernel, specifically with the tun/tap sockets having their socket UID hardcoded to 0 due to a type confusion in their initialization function. This could lead to tun/tap sockets being incorrectly treated in filtering/routing decisions, possibly bypassing network filters. The flaw is also associated with the use of an inappropriate data structure description for reading data from memory in the tap open() function of the TAP virtual network adapter driver.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01204
CVE-2023-1076
DLA-3404-1
MGASA-2023-0148
MGASA-2023-0149
MGASA-2023-0295
MGASA-2023-0296
OESA-2023-1173
OESA-2023-1174
OESA-2023-1177
OESA-2023-1178
OPENSUSE-SU-2023_2646-1
OPENSUSE-SU-2023_2871-1
OPENSUSE-SU-2024:12779-1
OPENSUSE-SU-2024:13704-1
RHSA-2023:6583
RHSA-2023_6583
SUSE-SU-2023:0779-1
SUSE-SU-2023:1608-1
SUSE-SU-2023:1609-1
SUSE-SU-2023:1710-1
SUSE-SU-2023:1800-1
SUSE-SU-2023:1801-1
SUSE-SU-2023:1803-1
SUSE-SU-2023:1811-1
SUSE-SU-2023:1848-1
SUSE-SU-2023:1894-1
SUSE-SU-2023:2232-1
SUSE-SU-2023:2646-1
SUSE-SU-2023:2809-1
SUSE-SU-2023:2871-1
USN-6033-1
USN-6171-1
USN-6172-1
USN-6185-1
USN-6187-1
USN-6207-1
USN-6222-1
USN-6223-1
USN-6256-1
USN-6385-1

Affected Products

Astra Linux
Linux Kernel
Linuxmint
Red Hat
Suse
Ubuntu