CVE-2023-44466
Summary
| CVE | CVE-2023-44466 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-29 06:15:00 UTC |
| Updated | 2023-11-16 16:15:00 UTC |
| Description | An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Linux |
Linux Kernel |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| libceph: harden msgr2.1 frame segment length checks · torvalds/linux@a282a2f · GitHub |
MISC |
github.com |
|
| security.netapp.com/advisory/ntap-20231116-0003 |
|
security.netapp.com |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| Linux Kernel: Ceph file system buffer overflow · Advisory · google/security-research · GitHub |
MISC |
github.com |
|
| [PATCH] libceph: harden msgr2.1 frame segment length checks — CEPH Filesystem Development |
MISC |
www.spinics.net |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199809 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6416-1)
- 199814 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6416-2)
- 199840 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-6416-3)
- 199844 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6445-1)
- 199858 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6445-2)
- 199879 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6464-1)
- 199883 Ubuntu Security Notification for Linux kernel (NVIDIA) Vulnerabilities (USN-6466-1)
- 199957 Ubuntu Security Notification for Linux kernel (StarFive) Vulnerabilities (USN-6520-1)
- 907398 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (30056)
- 907529 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (30056-1)