CVE-2023-3090
Out-of-bounds write in Linux kernel's ipvlan network driver
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.
Una vulnerabilidad de escritura fuera de los límites de la memoria en el controlador de red ipvlan del kernel de Linux se puede explotar para lograr la escalada de privilegios locales. La escritura fuera de los límites se debe a la falta de inicialización skb->cb en el controlador de red ipvlan. La vulnerabilidad es accesible si CONFIG_IPVLAN está habilitada. Recomendamos actualizar al anterior commit 90cbed5247439a966b645b34eb0a2e037836ea8e.
A flaw was found in the IPVLAN network driver in the Linux kernel. This issue is caused by missing skb->cb initialization in `__ip_options_echo` and can lead to an out-of-bounds write stack overflow. This may allow a local user to cause a denial of service or potentially achieve local privilege escalation.
A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.
This update for the Linux Kernel 5.14.21-150400_24_46 fixes several issues. The following security issues were fixed. Fixed a use-after-free in Netfilter nf_tables when processing batch requests. Fixed a flaw in the networking subsystem within the handling of the RPL protocol. Fixed a use-after-free in vcs_read in drivers/tty/vt/vc_screen.c. Fixed an out-of-bounds memory access flaw in nft_byteorder that could allow a local attacker to escalate their privilege. Fixed a type confusion in pick_next_rt_entity, that could cause memory corruption. Fixed an out-of-boundary read in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA. Fixed a heap out-of-bounds write in the ipvlan network driver.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-06-03 CVE Reserved
- 2023-06-28 CVE Published
- 2025-03-05 CVE Updated
- 2025-03-05 First Exploit
- 2025-06-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
- CAPEC-233: Privilege Escalation
References (11)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/174577/Kernel-Live-Patch-Security-Notice-LSN-0097-1.html | Third Party Advisory |
|
http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSN-0098-1.html | Third Party Advisory |
|
https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html | Mailing List |
|
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html | Mailing List |
|
https://security.netapp.com/advisory/ntap-20230731-0002 | Third Party Advisory |
|
https://www.debian.org/security/2023/dsa-5448 | Third Party Advisory |
|
https://www.debian.org/security/2023/dsa-5480 | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=90cbed5247439a966b645b34eb0a2e037836ea8e | 2025-03-05 |
URL | Date | SRC |
---|---|---|
https://kernel.dance/90cbed5247439a966b645b34eb0a2e037836ea8e | 2024-06-26 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2023-3090 | 2023-10-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2218672 | 2023-10-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.19 < 4.14.316 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.19 < 4.14.316" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.15 < 4.19.284 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.15 < 4.19.284" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.20 < 5.4.244 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.20 < 5.4.244" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.5 < 5.10.181 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.5 < 5.10.181" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.11 < 5.15.113 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.11 < 5.15.113" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.16 < 6.1.30 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.16 < 6.1.30" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.2 < 6.3.4 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.2 < 6.3.4" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 12.0 Search vendor "Debian" for product "Debian Linux" and version "12.0" | - |
Affected
|