Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2156

Опубликовано: 04 мая 2023
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.

A flaw was found in the Linux kernel's networking subsystem within the RPL protocol's handling. This issue results from the improper handling of user-supplied data, which can lead to an assertion failure. This flaw allows an unauthenticated, remote attacker to create a denial of service condition on the system.

Отчет

Red Hat Enterprise Linux 6, 7, and 8 are not affected by this flaw as they did not include RPL source routing support (upstream commit 8610c7c "net: ipv6: add support for rpl sr exthdr"). The flaw cannot be triggered if the rpl_seg_enabled sysctl is set to 0. Please note that the rpl_seg_enabled sysctl is not enabled by default in Red Hat Enterprise Linux 9. As such, the impact has been lowered to Moderate on Red Hat Enterprise Linux 9.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernel-rtWill not fix
Red Hat Enterprise Linux 9kernelFixedRHSA-2023:658307.11.2023
Red Hat Enterprise Linux 9kernelFixedRHSA-2023:658307.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2196292kernel: net: IPv6 RPL protocol reachable assertion leads to DoS

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.

CVSS3: 7.5
nvd
около 2 лет назад

A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.

CVSS3: 7.5
debian
около 2 лет назад

A flaw was found in the networking subsystem of the Linux kernel withi ...

suse-cvrf
почти 2 года назад

Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP5)

CVSS3: 7.5
github
около 2 лет назад

A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.

7.5 High

CVSS3