CVE-2023-31436
Published on: Not Yet Published
Last Modified on: 08/18/2023 06:39:00 PM UTC
Certain versions of Linux Kernel from Linux contain the following vulnerability:
qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.
- CVE-2023-31436 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Kernel Live Patch Security Notice LSN-0095-1 ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
CVE-2023-31436 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Patch "net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg" has been added to the 6.2-stable tree — Linux Stable Commits | www.spinics.net text/html |
![]() |
Kernel Live Patch Security Notice LSN-0096-1 ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
net: sched: sch_qfq: prevent slab-out-of-bounds in qfq_activate_agg · torvalds/linux@3037933 · GitHub | github.com text/html |
![]() |
[SECURITY] [DLA 3446-1] linux-5.10 security update | lists.debian.org text/html |
![]() |
Debian -- Security Information -- DSA-5402-1 linux | www.debian.org Depreciated Link text/html |
![]() |
cdn.kernel.org text/plain |
![]() |
Related QID Numbers
- 181781 Debian Security Update for linux (DSA 5402-1)
- 181828 Debian Security Update for linux-5.10 (DLA 3446-1)
- 183056 Debian Security Update for linux (CVE-2023-31436)
- 199382 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6127-1)
- 199384 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6132-1)
- 199386 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6131-1)
- 199390 Ubuntu Security Notification for Linux kernel (Azure CVM) Vulnerabilities (USN-6135-1)
- 199406 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6150-1)
- 199413 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6162-1)
- 199421 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6173-1)
- 199422 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6175-1)
- 199437 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6186-1)
- 199465 Ubuntu Security Notification for Linux kernel (Xilinx ZynqMP) Vulnerabilities (USN-6222-1)
- 199471 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6130-1)
- 199539 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6149-1)
- 199614 Ubuntu Security Notification for Linux kernel (IoT) Vulnerabilities (USN-6256-1)
- 355083 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2023-032
- 355088 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2023-045
- 355100 Amazon Linux Security Advisory for kernel : ALAS2-2023-2035
- 355101 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-018
- 355103 Amazon Linux Security Advisory for kernel : ALAS-2023-1744
- 355237 Amazon Linux Security Advisory for kernel : ALAS2023-2023-179
- 378710 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0079)
- 673214 EulerOS Security Update for kernel (EulerOS-SA-2023-2383)
- 673232 EulerOS Security Update for kernel (EulerOS-SA-2023-2357)
- 673261 EulerOS Security Update for kernel (EulerOS-SA-2023-2614)
- 673272 EulerOS Security Update for kernel (EulerOS-SA-2023-2584)
- 754097 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2507-1)
- 754105 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2537-1)
- 754106 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2534-1)
- 754110 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2538-1)
- 754120 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2611-1)
- 754145 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2651-1)
- 906892 Common Base Linux Mariner (CBL-Mariner) Security Update for hyperv-daemons (26659-1)
- 906909 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (26391-1)
- 906926 Common Base Linux Mariner (CBL-Mariner) Security Update for hyperv-daemons (26668-1)
- 906962 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (26385-1)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Linux | Linux Kernel | All | All | All | All |
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-31436 : qfq_change_class in net/sched/sch_qfq.c in the #Linux #kernel before 6.2.13 allows an out-of-bound… twitter.com/i/web/status/1… | 2023-04-28 02:03:59 |
![]() |
Linux Kernel unspecified | CVE-2023-31436 - redpacketsecurity.com/linux-kernel-u… #CVE #Vulnerability #OSINT #ThreatIntel #Cyber | 2023-04-29 09:03:26 |
![]() |
Google Kubernetes Engine update on June 27, 2023 cloud.google.com/kubernetes-eng… #googlecloud With CVE-2023-31436, an out-o… twitter.com/i/web/status/1… | 2023-06-27 15:03:00 |
![]() |
Anthos clusters on Azure update on June 27, 2023 cloud.google.com/anthos/cluster… #googlecloud With CVE-2023-31436, an out-o… twitter.com/i/web/status/1… | 2023-06-27 16:30:31 |
![]() |
Security bulletin With CVE-2023-31436, an out-of-bounds memory access flaw was found in the Linux kernel's traffic… twitter.com/i/web/status/1… | 2023-06-27 20:30:28 |
![]() |
[2023-06-27][Anthos clusters on Azure]An out-of-bounds memory access flaw (CVE-2023-31436) in Linux kernel's QoS su… twitter.com/i/web/status/1… | 2023-06-29 09:00:07 |