PT-2023-8122 · Linux+6 · Linux Kernel+6

Published

2023-12-12

·

Updated

2024-11-21

·

CVE-2023-51782

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.8
Description The issue is related to the rose ioctl function in the net/rose/af rose.c module of the Linux kernel, which implements the Amateur Radio X.25 PLP (Rose) protocol. It is caused by a use-after-free error due to a race condition in the rose accept function. This can allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions prior to 6.6.8, update to version 6.6.8 or later to resolve the issue. As a temporary workaround, consider disabling the rose ioctl function until a patch is available. Restrict access to the net/rose/af rose.c module to minimize the risk of exploitation.

Fix

DoS

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-14046
ALT-PU-2024-6818
AZL-33344
BDU:2024-00101
CVE-2023-51782
DLA-3710-1
DLA-3711-1
DSA-5593-1
DSA-5594-1
OESA-2024-1067
OESA-2024-1068
OESA-2024-1069
OESA-2024-1085
OESA-2024-1086
OESA-2024-1087
OPENSUSE-SU-2024_0469-1
OPENSUSE-SU-2024_0515-1
SUSE-SU-2024:0463-1
SUSE-SU-2024:0468-1
SUSE-SU-2024:0469-1
SUSE-SU-2024:0474-1
SUSE-SU-2024:0476-1
SUSE-SU-2024:0478-1
SUSE-SU-2024:0483-1
SUSE-SU-2024:0484-1
SUSE-SU-2024:0514-1
SUSE-SU-2024:0515-1
SUSE-SU-2024:0516-1
SUSE-SU-2024:1669-1
USN-6639-1
USN-6646-1
USN-6647-1
USN-6647-2
USN-6680-1
USN-6680-2
USN-6680-3
USN-6681-1
USN-6681-2
USN-6681-3
USN-6681-4
USN-6686-1
USN-6686-2
USN-6686-3
USN-6686-4
USN-6686-5
USN-6705-1
USN-6716-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu