PT-2023-8498 · Linux+10 · Linux Kernel+10
Published
2023-01-13
·
Updated
2026-01-15
·
CVE-2023-52340
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.3
Description
The issue is related to the IPv6 implementation in the Linux kernel, specifically with the
net/ipv6/route.c file. It involves incorrect handling of boundary conditions, potentially allowing a remote attacker to cause a denial of service. This can occur when IPv6 packets are sent in a loop via a raw socket, leading to "network is unreachable" errors. The max size threshold can be easily consumed, contributing to this problem.Recommendations
For Linux kernel versions prior to 6.3, update to version 6.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of raw sockets to minimize the risk of exploitation. Additionally, monitor network traffic for signs of attempted denial-of-service attacks and implement measures to prevent such attacks.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu