CVE-2023-2006
Summary
| CVE | CVE-2023-2006 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-24 21:15:00 UTC |
| Updated | 2023-08-25 15:23:00 UTC |
| Description | A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| rxrpc: Fix race between conn bundle lookup and bundle removal [ZDI-CA… · torvalds/linux@3bcd6c7 · GitHub |
MISC |
github.com |
|
| ZDI-23-439 | Zero Day Initiative |
MISC |
www.zerodayinitiative.com |
|
| 2189112 – (CVE-2023-2006) CVE-2023-2006 kernel: rxrpc: race condition between connection bundle lookup and removal |
MISC |
bugzilla.redhat.com |
|
| CVE-2023-2006 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181849 Debian Security Update for linux (CVE-2023-2006)
- 378892 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0114)
- 379043 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0136)
- 906933 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (26376-1)
- 906972 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (26375-1)