CVE-2023-3090
Summary
| CVE | CVE-2023-3090 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-28 20:15:00 UTC |
| Updated | 2023-10-26 18:27:00 UTC |
| Description | A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation.
The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled.
We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160818 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12688)
- 160837 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-4377)
- 160934 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-5244)
- 199469 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6231-1)
- 199604 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6246-1)
- 199608 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6250-1)
- 199612 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6255-1)
- 199613 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6251-1)
- 199615 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6252-1)
- 199617 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6254-1)
- 199618 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6260-1)
- 199623 Ubuntu Security Notification for Linux kernel (IoT) Vulnerabilities (USN-6261-1)
- 199764 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6385-1)
- 241878 Red Hat Update for kernel security (RHSA-2023:4377)
- 241880 Red Hat Update for kpatch-patch (RHSA-2023:4380)
- 241886 Red Hat Update for kernel-rt (RHSA-2023:4378)
- 241926 Red Hat Update for kernel (RHSA-2023:4515)
- 241929 Red Hat Update for kpatch-patch (RHSA-2023:4516)
- 242062 Red Hat Update for kpatch-patch (RHSA-2023:5221)
- 242070 Red Hat Update for kernel security (RHSA-2023:5244)
- 242075 Red Hat Update for kernel-rt (RHSA-2023:5255)
- 242141 Red Hat Update for kpatch-patch (RHSA-2023:5548)
- 242151 Red Hat Update for kernel security (RHSA-2023:5627)
- 355838 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-138
- 355845 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-141
- 355848 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-135
- 355849 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-136
- 355850 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-139
- 355854 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-137
- 355858 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-140
- 355860 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-134
- 356518 Amazon Linux Security Advisory for kernel-livepatch : ALAS2023LIVEPATCH-2023-016
- 356529 Amazon Linux Security Advisory for kernel-livepatch : ALAS2023LIVEPATCH-2023-017
- 356536 Amazon Linux Security Advisory for kernel-livepatch : ALAS2023LIVEPATCH-2023-019
- 356543 Amazon Linux Security Advisory for kernel-livepatch : ALAS2023LIVEPATCH-2023-018
- 378889 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0036)
- 378892 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0114)
- 379043 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0136)
- 390286 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0018)
- 6000136 Debian Security Update for linux (DLA 3508-1)
- 6000207 Debian Security Update for linux (DSA 5448-1)
- 6000212 Debian Security Update for linux (DSA 5480-1)
- 6000265 Debian Security Update for linux-5.10 (DLA 3623-1)
- 673372 EulerOS Security Update for kernel (EulerOS-SA-2023-2787)
- 673498 EulerOS Security Update for kernel (EulerOS-SA-2023-3132)
- 754160 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2808-1)
- 754167 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2822-1)
- 754168 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2830-1)
- 754170 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2834-1)
- 754183 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2859-1)
- 754829 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 24 for SLE 15 SP3) (SUSE-SU-2023:3594-1)
- 754830 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 36 for SLE 15 SP1) (SUSE-SU-2023:3596-1)
- 754831 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 27 for SLE 15 SP3) (SUSE-SU-2023:3595-1)
- 754834 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 25 for SLE 15 SP3) (SUSE-SU-2023:3607-1)
- 754835 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 37 for SLE 15 SP1) (SUSE-SU-2023:3603-1)
- 754839 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 37 for SLE 15 SP2) (SUSE-SU-2023:3621-1)
- 754840 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 36 for SLE 15 SP2) (SUSE-SU-2023:3620-1)
- 754841 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 29 for SLE 15 SP3) (SUSE-SU-2023:3623-1)
- 754842 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 35 for SLE 15 SP2) (SUSE-SU-2023:3612-1)
- 754844 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 32 for SLE 15 SP3) (SUSE-SU-2023:3628-1)
- 754845 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 30 for SLE 15 SP3) (SUSE-SU-2023:3627-1)
- 754847 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 33 for SLE 15 SP3) (SUSE-SU-2023:3631-1)
- 754848 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 0 for SLE 15 SP5) (SUSE-SU-2023:3630-1)
- 754852 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 12 for SLE 15 SP4) (SUSE-SU-2023:3648-1)
- 754853 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 11 for SLE 15 SP4) (SUSE-SU-2023:3647-1)
- 754854 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 8 for SLE 15 SP4) (SUSE-SU-2023:3644-1)
- 754859 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 13 for SLE 15 SP4) (SUSE-SU-2023:3657-1)
- 754871 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 1 for SLE 15 SP5) (SUSE-SU-2023:3676-1)
- 754872 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 7 for SLE 15 SP4) (SUSE-SU-2023:3675-1)
- 754873 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 0 for SLE 15 SP5) (SUSE-SU-2023:3671-1)
- 754874 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 6 for SLE 15 SP4) (SUSE-SU-2023:3668-1)
- 907055 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27355-1)
- 907157 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27350-1)
- 941213 AlmaLinux Security Update for kernel (ALSA-2023:4377)
- 941214 AlmaLinux Security Update for kernel-rt (ALSA-2023:4378)
- 941276 AlmaLinux Security Update for kernel (ALSA-2023:5244)
- 960961 Rocky Linux Security Update for kernel-rt (RLSA-2023:4378)
- 961022 Rocky Linux Security Update for kernel (RLSA-2023:5244)