CVE-2023-3090
Published on: Not Yet Published
Last Modified on: 09/11/2023 07:15:00 PM UTC
Certain versions of Debian Linux from Debian contain the following vulnerability:
A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.
- CVE-2023-3090 has been assigned by
secu[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Linux - Kernel version < 6.4
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
No Description Provided | kernel.dance text/html Inactive LinkNot Archived |
![]() |
Kernel Live Patch Security Notice LSN-0097-1 ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
Debian -- Security Information -- DSA-5480-1 linux | www.debian.org Depreciated Link text/html |
![]() |
[SECURITY] [DLA 3508-1] linux security update | lists.debian.org text/html |
![]() |
CVE-2023-3090 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
kernel/git/torvalds/linux.git - Linux kernel source tree | git.kernel.org text/html |
![]() |
Debian -- Security Information -- DSA-5448-1 linux | www.debian.org Depreciated Link text/html |
![]() |
Related QID Numbers
- 160818 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12688)
- 160837 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-4377)
- 199469 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6231-1)
- 199604 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6246-1)
- 199608 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6250-1)
- 199612 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6255-1)
- 199613 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6251-1)
- 199615 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6252-1)
- 199617 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6254-1)
- 199618 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6260-1)
- 199623 Ubuntu Security Notification for Linux kernel (IoT) Vulnerabilities (USN-6261-1)
- 241878 Red Hat Update for kernel security (RHSA-2023:4377)
- 241880 Red Hat Update for kpatch-patch (RHSA-2023:4380)
- 241886 Red Hat Update for kernel-rt (RHSA-2023:4378)
- 241926 Red Hat Update for kernel (RHSA-2023:4515)
- 241929 Red Hat Update for kpatch-patch (RHSA-2023:4516)
- 355838 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-138
- 355845 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-141
- 355848 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-135
- 355849 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-136
- 355850 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-139
- 355854 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-137
- 355858 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-140
- 355860 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-134
- 390286 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0018)
- 754160 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2808-1)
- 754167 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2822-1)
- 754168 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2830-1)
- 754170 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2834-1)
- 754183 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2859-1)
- 907055 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27355-1)
- 907157 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27350-1)
- 941213 AlmaLinux Security Update for kernel (ALSA-2023:4377)
- 941214 AlmaLinux Security Update for kernel-rt (ALSA-2023:4378)
- 960961 Rocky Linux Security Update for kernel-rt (RLSA-2023:4378)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Debian | Debian Linux | 12.0 | All | All | All |
Operating System | Linux | Linux Kernel | All | All | All | All |
- cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-3090 : A heap out-of-bounds write vulnerability in the #Linux Kernel ipvlan network driver can be exploite… twitter.com/i/web/status/1… | 2023-06-28 20:02:29 |
![]() |
CVE-2023-3090 (CVSS:7.8, HIGH) is Received. A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan net… twitter.com/i/web/status/1… | 2023-06-29 06:00:13 |