CVE-2023-34256
Summary
| CVE | CVE-2023-34256 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-31 20:15:00 UTC |
| Updated | 2023-11-15 02:51:00 UTC |
| Description | ** DISPUTED ** An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the block device while it is mounted by the filesystem" access. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.3 |
MISC |
cdn.kernel.org |
|
| [SECURITY] [DLA 3508-1] linux security update |
MLIST |
lists.debian.org |
|
| KASAN: slab-out-of-bounds Read in ext4_group_desc_csum |
MISC |
syzkaller.appspot.com |
|
| [SECURITY] [DLA 3623-1] linux-5.10 security update |
MLIST |
lists.debian.org |
|
| 1211895 – (CVE-2023-34256) VUL-0: CVE-2023-34256: kernel: potential slab-out-of-bounds in ext4_group_desc_csum |
MISC |
bugzilla.suse.com |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160766 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12566)
- 160767 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12565)
- 200199 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6700-1)
- 200202 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6701-1)
- 200209 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-6701-2)
- 200217 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-6700-2)
- 200222 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6701-3)
- 200244 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-6701-4)
- 355531 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2023-034
- 355532 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-021
- 355536 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2023-047
- 355545 Amazon Linux Security Advisory for kernel : ALAS2-2023-2100
- 355557 Amazon Linux Security Advisory for kernel : ALAS-2023-1773
- 378889 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0036)
- 390285 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0017)
- 390286 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0018)
- 6000136 Debian Security Update for linux (DLA 3508-1)
- 6000265 Debian Security Update for linux-5.10 (DLA 3623-1)
- 6140228 AWS Bottlerocket Security Update for kernel (GHSA-p98r-538v-jgw5)
- 673261 EulerOS Security Update for kernel (EulerOS-SA-2023-2614)
- 673272 EulerOS Security Update for kernel (EulerOS-SA-2023-2584)
- 673354 EulerOS Security Update for kernel (EulerOS-SA-2023-2843)
- 673372 EulerOS Security Update for kernel (EulerOS-SA-2023-2787)
- 673496 EulerOS Security Update for kernel (EulerOS-SA-2023-2860)
- 673498 EulerOS Security Update for kernel (EulerOS-SA-2023-3132)
- 673604 EulerOS Security Update for kernel (EulerOS-SA-2023-2811)
- 907004 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27052-1)
- 907022 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27063-1)