PT-2023-4315 · Linux+6 · Linux+6

Ross Lagerwall

·

Published

2023-08-08

·

Updated

2024-10-11

·

CVE-2023-34319

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux (affected versions not specified)
Description The issue is related to the Linux netback driver, which was modified to handle a frontend splitting a packet in a way that not all headers come in one piece. However, the introduced logic did not account for the extreme case of the entire packet being split into many pieces, yet still being smaller than the area that keeps all possible headers together. This unusual packet would trigger a buffer overrun in the driver. The xenvif get requests() function in the drivers/net/xen-netback/netback.c module is specifically mentioned as being related to the issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8473
BDU:2023-04650
CVE-2023-34319
DLA-3623-1
DLA-3710-1
DSA-5480-1
DSA-5492-1
LSN-0099-1
MGASA-2023-0250
MGASA-2023-0251
MGASA-2023-0328
MGASA-2023-0331
OESA-2023-1584
OESA-2023-1585
OESA-2023-1586
OESA-2023-1587
OESA-2023-1588
OPENSUSE-SU-2023_3392-1
OPENSUSE-SU-2023_3599-1
OPENSUSE-SU-2023_3599-2
OPENSUSE-SU-2023_3600-1
OPENSUSE-SU-2023_3600-2
OPENSUSE-SU-2023_3656-1
OPENSUSE-SU-2023_3682-1
OPENSUSE-SU-2023_3683-1
OPENSUSE-SU-2023_3683-2
OPENSUSE-SU-2023_3684-1
OPENSUSE-SU-2023_3704-1
OPENSUSE-SU-2023_3704-2
OPENSUSE-SU-2023_3964-1
OPENSUSE-SU-2023_3969-1
OPENSUSE-SU-2023_3971-1
OPENSUSE-SU-2023_3988-1
SUSE-SU-2023:3390-1
SUSE-SU-2023:3392-1
SUSE-SU-2023:3599-1
SUSE-SU-2023:3599-2
SUSE-SU-2023:3600-1
SUSE-SU-2023:3600-2
SUSE-SU-2023:3601-1
SUSE-SU-2023:3656-1
SUSE-SU-2023:3681-1
SUSE-SU-2023:3682-1
SUSE-SU-2023:3684-1
SUSE-SU-2023:3705-1
SUSE-SU-2023:3785-1
SUSE-SU-2023:3964-1
SUSE-SU-2023:3969-1
SUSE-SU-2023:3971-1
SUSE-SU-2023:3988-1
USN-6343-1
USN-6439-1
USN-6439-2
USN-6440-1
USN-6440-2
USN-6440-3
USN-6441-1
USN-6441-2
USN-6441-3
USN-6442-1
USN-6444-1
USN-6444-2
USN-6445-1
USN-6445-2
USN-6446-1
USN-6446-2
USN-6446-3
USN-6466-1

Affected Products

Alt Linux
Astra Linux
Linux
Linuxmint
Red Os
Suse
Ubuntu