CVE-2023-42752
Summary
| CVE | CVE-2023-42752 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-13 02:15:00 UTC |
| Updated | 2023-11-07 04:21:00 UTC |
| Description | An integer overflow flaw was found in the Linux kernel. This issue leads to the kernel allocating `skb_shared_info` in the userspace, which is exploitable in systems without SMAP protection since `skb_shared_info` contains references to function pointers. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Linux |
Linux Kernel |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| cve-details |
MISC |
access.redhat.com |
|
| kernel/git/netdev/net.git - Netdev Group's networking tree |
MISC |
git.kernel.org |
|
| 2239828 – (CVE-2023-42752) CVE-2023-42752 kernel: integer overflow in igmpv3_newpack leading to exploitable memory access |
MISC |
bugzilla.redhat.com |
|
| kernel/git/netdev/net.git - Netdev Group's networking tree |
MISC |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161237 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-13043)
- 161334 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2024-12110)
- 199841 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6444-1)
- 199842 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6440-1)
- 199843 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6439-1)
- 199844 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6445-1)
- 199845 Ubuntu Security Notification for Linux kernel (BlueField) Vulnerabilities (USN-6442-1)
- 199846 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6441-1)
- 199847 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6443-1)
- 199848 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6446-1)
- 199849 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-6440-2)
- 199854 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-6441-2)
- 199855 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-6439-2)
- 199858 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6445-2)
- 199859 Ubuntu Security Notification for Linux kernel (StarFive) Vulnerabilities (USN-6444-2)
- 199861 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6446-2)
- 199864 Ubuntu Security Notification for Linux kernel (HWE) Vulnerabilities (USN-6440-3)
- 199868 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-6446-3)
- 199872 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6441-3)
- 199874 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6460-1)
- 199883 Ubuntu Security Notification for Linux kernel (NVIDIA) Vulnerabilities (USN-6466-1)
- 356371 Amazon Linux Security Advisory for kernel : ALAS2023-2023-356
- 356919 Amazon Linux Security Advisory for kernel-livepatch : ALAS2023LIVEPATCH-2023-026
- 356923 Amazon Linux Security Advisory for kernel-livepatch : ALAS2023LIVEPATCH-2023-024
- 356924 Amazon Linux Security Advisory for kernel-livepatch : ALAS2023LIVEPATCH-2023-025
- 390294 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2024-0002)
- 6140348 AWS Bottlerocket Security Update for kernel (GHSA-hjp2-xpq4-6r4r)
- 907652 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (31521-1)