PT-2023-5513 · Linux+10 · Linux Kernel+10

Kyle Zeng

·

Published

2023-02-16

·

Updated

2024-11-21

·

CVE-2023-42755

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 4.14.326 Linux kernel versions prior to 4.19.295 Linux kernel versions prior to 5.4.257 Linux kernel versions prior to 5.10.197 Linux kernel versions prior to 5.15.133 Linux kernel versions prior to 6.1.55 Linux kernel versions prior to 6.3
Description A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the rsvp classify function. This issue may allow a local user to crash the system and cause a denial of service.
Recommendations For Linux kernel versions prior to 4.14.326, update to version 4.14.326 or later. For Linux kernel versions prior to 4.19.295, update to version 4.19.295 or later. For Linux kernel versions prior to 5.4.257, update to version 5.4.257 or later. For Linux kernel versions prior to 5.10.197, update to version 5.10.197 or later. For Linux kernel versions prior to 5.15.133, update to version 5.15.133 or later. For Linux kernel versions prior to 6.1.55, update to version 6.1.55 or later. For Linux kernel versions prior to 6.3, update to version 6.3 or later.

Exploit

Fix

DoS

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2950
ALSA-2024:3138
ALT-PU-2024-14046
ALT-PU-2024-6818
AZL-31269
BDU:2023-06161
CESA-2024_2950
CESA-2024_3138
CVE-2023-42755
DLA-3623-1
DLA-3710-1
INFSA-2024_2950
INFSA-2024_3138
OESA-2023-1741
RHSA-2024:2950
RHSA-2024:3138
RHSA-2024_2950
RHSA-2024_3138
RLSA-2024:2950
RLSA-2024:3138
SUSE-SU-2024:1979-1
SUSE-SU-2024:1983-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2184-1
SUSE-SU-2024:2190-1
USN-6439-1
USN-6439-2
USN-6440-1
USN-6440-2
USN-6440-3
USN-6441-1
USN-6441-2
USN-6441-3
USN-6442-1
USN-6443-1
USN-6444-1
USN-6444-2
USN-6445-1
USN-6445-2
USN-6446-1
USN-6446-2
USN-6446-3
USN-6460-1
USN-6466-1
ZDI-24-591

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu