CVE-2023-3611
Summary
| CVE | CVE-2023-3611 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-21 21:15:00 UTC |
| Updated | 2023-10-26 20:28:00 UTC |
| Description | An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation.
The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes without bounds checks.
We recommend upgrading past commit 3e337087c3b5805fe0b8a46ba622a962880b5d64. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3623-1] linux-5.10 security update |
MISC |
lists.debian.org |
|
| Debian -- Security Information -- DSA-5480-1 linux |
MISC |
www.debian.org |
|
| Debian -- Security Information -- DSA-5492-1 linux |
MISC |
www.debian.org |
|
| CVE-2023-3611 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
MISC |
security.netapp.com |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| kernel.dance/3e337087c3b5805fe0b8a46ba622a962880b5d64 |
MISC |
kernel.dance |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160949 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12842)
- 161147 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-7077)
- 161194 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-7423)
- 199651 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6285-1)
- 199764 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6385-1)
- 199775 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6341-1)
- 199784 Ubuntu Security Notification for Linux kernel (BlueField) Vulnerabilities (USN-6397-1)
- 242434 Red Hat Update for kernel-rt security (RHSA-2023:6901)
- 242451 Red Hat Update for kernel security (RHSA-2023:7077)
- 242498 Red Hat Update for kernel-rt (RHSA-2023:7424)
- 242501 Red Hat Update for kernel (RHSA-2023:7423)
- 242502 Red Hat Update for kpatch-patch (RHSA-2023:7419)
- 242728 Red Hat Update for kpatch-patch (RHSA-2024:0378)
- 242769 Red Hat Update for kpatch-patch (RHSA-2024:0554)
- 242789 Red Hat Update for kernel (RHSA-2024:0575)
- 242855 Red Hat Update for kernel (RHSA-2024:0412)
- 243055 Red Hat Update for kernel (RHSA-2024:1268)
- 243057 Red Hat Update for kpatch-patch (RHSA-2024:1278)
- 243058 Red Hat Update for kernel-rt (RHSA-2024:1269)
- 243076 Red Hat Update for kernel (RHSA-2024:1367)
- 243085 Red Hat Update for kpatch-patch (RHSA-2024:1377)
- 243096 Red Hat Update for kernel-rt (RHSA-2024:1382)
- 257270 Centos Security Update for kernel
- 257295 CentOS Security Update for kernel (CESA-2023:7423)
- 355761 Amazon Linux Security Advisory for kernel : ALAS-2023-1792
- 355771 Amazon Linux Security Advisory for kernel : ALAS2-2023-2179
- 355795 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2023-038
- 355796 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-025
- 355798 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2023-050
- 355815 Amazon Linux Security Advisory for kernel : ALAS2023-2023-285
- 378889 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0036)
- 378892 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0114)
- 379043 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0136)
- 390290 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0023)
- 6000212 Debian Security Update for linux (DSA 5480-1)
- 6000220 Debian Security Update for linux (DSA 5492-1)
- 6000265 Debian Security Update for linux-5.10 (DLA 3623-1)
- 6000429 Debian Security Update for linux (DLA 3710-1)
- 6140148 AWS Bottlerocket Security Update for kernel (GHSA-g6v3-rqj6-5h8m)
- 673354 EulerOS Security Update for kernel (EulerOS-SA-2023-2843)
- 673372 EulerOS Security Update for kernel (EulerOS-SA-2023-2787)
- 673449 EulerOS Security Update for kernel (EulerOS-SA-2023-2898)
- 673496 EulerOS Security Update for kernel (EulerOS-SA-2023-2860)
- 673498 EulerOS Security Update for kernel (EulerOS-SA-2023-3132)
- 673604 EulerOS Security Update for kernel (EulerOS-SA-2023-2811)
- 673970 EulerOS Security Update for kernel (EulerOS-SA-2023-2879)
- 754275 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3309-1)
- 754281 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3349-1)
- 907117 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27723-1)
- 907213 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27675-1)
- 941453 AlmaLinux Security Update for kernel (ALSA-2023:7077)