Back

MEDIUM

Kernel: vmxnet3: null pointer dereference in vmxnet3_rq_cleanup()

Published Aug 21, 2023

Description

A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel. This issue may allow a local attacker with normal user privilege to cause a denial of service due to a missing sanity check during cleanup.

Affected products

Remediation

Vendor solution

In order to mitigate this issue, prevent the affected code from being loaded by blacklisting the kernel module "vmxnet3". For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 ~~~ Exploiting this flaw will require CAP_NET_ADMIN access privilege in any user or network namespace. ~~~

Red Hat statement

For the Red Hat Enterprise Linux 8.7 (and higher versions) the patch that resolves the problem already applied (so no need to update then). Similar for the Red Hat Enterprise Linux 9.1 (and higher versions) the patch that resolves the problem already applied. Only Red Hat Enterprise Linux 9.0 affected.

Red Hat mitigation

In order to mitigate this issue, prevent the affected code from being loaded by blacklisting the kernel module "vmxnet3". For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278 ~~~ Exploiting this flaw will require CAP_NET_ADMIN access privilege in any user or network namespace. ~~~

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 21, 2023
Updated Nov 15, 2025
Reserved Aug 21, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 14, 2022