kernel: UAF during login when accessing the shost ipaddress
Published Apr 19, 2023
6.6
MEDIUMCVSS 3.1
EPSS 0.25%
Description
A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux Kernel. In this flaw an attacker could leak kernel internal information.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Linux Kernel version prior to Kernel 6.2 RC6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
- < 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
- 6.2
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.11.1.el8_9
Fixed · RHSA-2024:0113
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.11.1.rt7.313.el8_9
Fixed · RHSA-2024:0134
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.120.1.el8_2
Fixed · RHSA-2024:0403
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-0:4.18.0-193.120.1.el8_2
Fixed · RHSA-2024:0403
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-rt-0:4.18.0-193.120.1.rt13.171.el8_2
Fixed · RHSA-2024:0402
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kernel-0:4.18.0-193.120.1.el8_2
Fixed · RHSA-2024:0403
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.120.1.el8_4
Fixed · RHSA-2024:0562
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-0:4.18.0-305.120.1.el8_4
Fixed · RHSA-2024:0562
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-rt-0:4.18.0-305.120.1.rt7.196.el8_4
Fixed · RHSA-2024:0563
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kernel-0:4.18.0-305.120.1.el8_4
Fixed · RHSA-2024:0562
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.43.1.el8_8
Fixed · RHSA-2024:0575
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.85.1.el9_0
Fixed · RHSA-2024:0432
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.85.1.rt21.156.el9_0
Fixed · RHSA-2024:0431
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.48.1.el9_2
Fixed · RHSA-2024:0448
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.48.1.rt14.333.el9_2
Fixed · RHSA-2024:0439
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.11.1.el8_9 | Fixed | RHSA-2024:0113 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.11.1.rt7.313.el8_9 | Fixed | RHSA-2024:0134 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.120.1.el8_2 | Fixed | RHSA-2024:0403 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-0:4.18.0-193.120.1.el8_2 | Fixed | RHSA-2024:0403 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-rt-0:4.18.0-193.120.1.rt13.171.el8_2 | Fixed | RHSA-2024:0402 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kernel-0:4.18.0-193.120.1.el8_2 | Fixed | RHSA-2024:0403 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.120.1.el8_4 | Fixed | RHSA-2024:0562 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-0:4.18.0-305.120.1.el8_4 | Fixed | RHSA-2024:0562 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-rt-0:4.18.0-305.120.1.rt7.196.el8_4 | Fixed | RHSA-2024:0563 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kernel-0:4.18.0-305.120.1.el8_4 | Fixed | RHSA-2024:0562 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.43.1.el8_8 | Fixed | RHSA-2024:0575 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.85.1.el9_0 | Fixed | RHSA-2024:0432 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.85.1.rt21.156.el9_0 | Fixed | RHSA-2024:0431 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.48.1.el9_2 | Fixed | RHSA-2024:0448 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.48.1.rt14.333.el9_2 | Fixed | RHSA-2024:0439 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
This flaw can be mitigated by preventing the affected iscsi_tcp.ko kernel module from loading during the boot time, ensure the module is added into the blacklist file. ~~~ Refer: How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~
References (7)
- https://access.redhat.com/security/cve/CVE-2023-2162 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2187773 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html mailing-list
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2023-2162
- https://www.cve.org/CVERecord?id=CVE-2023-2162
- https://www.spinics.net/lists/linux-scsi/msg181542.html Mailing ListPatch
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-2162 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2187773 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html | mailing-list | |
| https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html | mailing-list | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-2162 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-2162 | ||
| https://www.spinics.net/lists/linux-scsi/msg181542.html | Mailing ListPatch |
Change history (0)
No recorded changes yet.