Kernel: xfrm: null pointer dereference in xfrm_update_ae_params()
Published Jul 25, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.45%
Description
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9 | affected |
Configuration 1
- 8.0
- 9.0
- 8.0
- 8.0
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- 10.0
- 12.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9
Fixed · RHSA-2023:6901
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.43.1.el8_8
Fixed · RHSA-2024:0575
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.8.1.el9_3
Fixed · RHSA-2023:6583
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | Fixed | RHSA-2023:6901 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.43.1.el8_8 | Fixed | RHSA-2024:0575 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | Fixed | RHSA-2023:6583 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- http://www.openwall.com/lists/oss-security/2023/08/10/1
- http://www.openwall.com/lists/oss-security/2023/08/10/3
- https://access.redhat.com/errata/RHSA-2023:6583 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6901 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7077 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0412 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0575 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-3772 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2218943 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44405 Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
- https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-3772
- https://www.cve.org/CVERecord?id=CVE-2023-3772
- https://www.debian.org/security/2023/dsa-5492
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data