VulnerabilityModified
CVE-2023-2156
This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
HIGH 7.5EPSS 6.13%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 6.13% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- linux/linux kernel · redhat/enterprise linux · fedoraproject/fedora · debian/debian linux
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2023/05/17/8Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/17/9Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/18/1Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/19/1Mailing List
- https://bugzilla.redhat.com/show_bug.cgi?id=2196292Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00001.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230622-0001/Mailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5448Third Party Advisory, VDB Entry
- https://www.debian.org/security/2023/dsa-5453Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-23-547/Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2023/05/17/8Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/17/9Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/18/1Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/19/1Mailing List
- https://bugzilla.redhat.com/show_bug.cgi?id=2196292Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00001.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230622-0001/Mailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5448Third Party Advisory, VDB Entry
- https://www.debian.org/security/2023/dsa-5453Third Party Advisory, VDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-23-547/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.