CVE-2023-42754
Summary
| CVE | CVE-2023-42754 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-05 19:15:00 UTC |
| Updated | 2023-11-07 04:21:00 UTC |
| Description | A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs. This issue may allow a local user with CAP_NET_ADMIN privileges to crash the system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| cve-details |
MISC |
access.redhat.com |
|
| oss-sec: [CVE-2023-42754] null pointer dereference in Linux kernel ipv4 stack |
MISC |
seclists.org |
|
| [SECURITY] Fedora 38 Update: kernel-6.5.6-200.fc38 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| 2239845 – (CVE-2023-42754) CVE-2023-42754 kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach() |
MISC |
bugzilla.redhat.com |
|
| [SECURITY] Fedora 37 Update: kernel-6.5.6-100.fc37 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 39 Update: kernel-6.5.6-300.fc39 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199881 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6461-1)
- 199936 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6494-1)
- 199970 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6494-2)
- 199976 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6534-1)
- 199979 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6532-1)
- 199980 Ubuntu Security Notification for Linux kernel Vulnerability (USN-6536-1)
- 199982 Ubuntu Security Notification for Linux kernel (GCP) Vulnerability (USN-6537-1)
- 199996 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6549-1)
- 199997 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6548-1)
- 199999 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6548-2)
- 200002 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6534-2)
- 200003 Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-6549-2)
- 200006 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-6548-3)
- 200007 Ubuntu Security Notification for Linux kernel (Low Latency) Vulnerabilities (USN-6549-3)
- 200010 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6534-3)
- 200024 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6549-4)
- 200035 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6549-5)
- 200037 Ubuntu Security Notification for Linux kernel (IoT) Vulnerabilities (USN-6548-5)
- 200113 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-6635-1)
- 284598 Fedora Security Update for kernel (FEDORA-2023-50bd7c9c12)
- 284599 Fedora Security Update for kernel (FEDORA-2023-830d9ec624)
- 285211 Fedora Security Update for kernel (FEDORA-2023-c3bb819677)
- 356530 Amazon Linux Security Advisory for kernel : ALAS2023-2023-385
- 356562 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2023-055
- 356569 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-028
- 356612 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2023-042
- 379043 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0136)
- 6000429 Debian Security Update for linux (DLA 3710-1)
- 6140258 AWS Bottlerocket Security Update for kernel (GHSA-88vc-qqhp-5j29)
- 6140310 AWS Bottlerocket Security Update for kernel (GHSA-f87x-mhxq-hfcc)
- 673534 EulerOS Security Update for kernel (EulerOS-SA-2024-1086)
- 673563 EulerOS Security Update for kernel (EulerOS-SA-2024-1144)
- 673595 EulerOS Security Update for kernel (EulerOS-SA-2023-3247)
- 673644 EulerOS Security Update for kernel (EulerOS-SA-2023-3336)
- 673692 EulerOS Security Update for kernel (EulerOS-SA-2023-3275)
- 673923 EulerOS Security Update for kernel (EulerOS-SA-2024-1062)
- 673995 EulerOS Security Update for kernel (EulerOS-SA-2024-1275)
- 674042 EulerOS Security Update for kernel (EulerOS-SA-2023-3304)
- 755059 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4035-1)
- 755060 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4031-1)
- 755063 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4032-1)
- 755082 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4058-1)
- 755083 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4057-1)
- 755085 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4072-1)
- 755086 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4071-1)
- 755096 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4093-1)
- 755229 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4072-2)
- 755235 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4377-1)
- 755564 SUSE Security Update for the linux kernel (SUSE-SU-2023:4348-1)
- 755565 SUSE Security Update for the linux kernel (SUSE-SU-2023:4347-1)
- 907569 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (31271-1)