PT-2024-14697 · Linux+5 · Linux Kernel+5

Published

2023-02-14

·

Updated

2026-05-26

·

CVE-2023-52700

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a kernel warning that occurs when sending a SYN message. The warning is caused by a lack of copy direction from the iterator viewpoint, which leads to a kernel stack trace. This is due to a commit that introduced sanity checks for copying from/to iov iterator. The issue is fixed by initializing the iov iterator with the correct copy direction when sending SYN or ACK without data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4211
ALSA-2024:4352
ALSA-2025_16880
AZL-67548
BDU:2025-14573
CESA-2024_4211
CESA-2024_4352
CVE-2023-52700
INFSA-2024_4211
INFSA-2024_4352
RHSA-2024:4211
RHSA-2024:4352
RHSA-2024_4211
RHSA-2024_4352
RLSA-2024:4211
RLSA-2024:4352
RXSA-2024:4211

Affected Products

Almalinux
Centos
Debian
Linux Kernel
Red Hat
Rocky Linux