CVE-2023-23455
Published on: Not Yet Published
Last Modified on: 03/03/2023 01:15:00 AM UTC
Certain versions of Debian Linux from Debian contain the following vulnerability:
atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).
- CVE-2023-23455 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[SECURITY] [DLA 3349-1] linux-5.10 security update | lists.debian.org text/html |
![]() |
Debian -- Security Information -- DSA-5324-1 linux | www.debian.org Depreciated Link text/html |
![]() |
kernel/git/torvalds/linux.git - Linux kernel source tree | git.kernel.org text/html |
![]() |
oss-security - Re: Type Confusion in Linux Kernel | www.openwall.com text/html |
![]() |
oss-security - Type Confusion in Linux Kernel | www.openwall.com text/html |
![]() |
Related QID Numbers
- 160500 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12160)
- 160505 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12196)
- 160506 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12199)
- 160508 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2023-12200)
- 160515 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2023-12207)
- 160516 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12206)
- 181491 Debian Security Update for linux (DSA 5324-1)
- 181618 Debian Security Update for linux-5.10 (DLA 3349-1)
- 199208 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5915-1)
- 199212 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5917-1)
- 199218 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-5927-1)
- 199224 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-5934-1)
- 199226 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-5939-1)
- 199230 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-5940-1)
- 199239 Ubuntu Security Notification for Linux kernel (IBM) Vulnerabilities (USN-5951-1)
- 354736 Amazon Linux Security Advisory for kernel : ALAS2-2023-1932
- 354739 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-013
- 354741 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2023-026
- 354775 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2023-042
- 390273 Oracle VM Server for x86 Security Update for kernel (OVMSA-2023-0004)
- 672747 EulerOS Security Update for kernel (EulerOS-SA-2023-1469)
- 753583 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0152-1)
- 753688 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0406-1)
- 753709 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0433-1)
- 905256 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13002)
- 905263 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13007)
- 906047 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13002-2)
- 906423 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13007-2)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Debian | Debian Linux | 11.0 | All | All | All |
Operating System | Linux | Linux Kernel | All | All | All | All |
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-23455 : atm_tc_enqueue in net/sched/sch_atm.c in the #Linux #kernel through 6.1.4 allows attackers to caus… twitter.com/i/web/status/1… | 2023-01-12 07:09:16 |
![]() |
March 01, 2023 GCP release notes | 2023-03-02 01:00:25 |
![]() |
March 02, 2023 GCP release notes | 2023-03-03 01:00:20 |