kernel: IGB driver inadequate buffer size for frames larger than MTU
Published Oct 15, 2023
7.5
HIGHCVSS 3.1
EPSS 0.62%
Description
An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU.
Affected products
No data.
Configuration 1
- ≥ 3.4 · < 4.14.326
- ≥ 4.15 · < 4.19.295
- ≥ 4.20 · < 5.4.257
- ≥ 5.5 · < 5.10.195
- ≥ 5.11 · < 5.15.132
- ≥ 5.16 · < 6.1.53
- ≥ 6.2 · < 6.4.16
- ≥ 6.5 · < 6.5.3
Configuration 2
- 10.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.114.2.el7
Fixed · RHSA-2024:1249
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.114.2.rt56.1266.el7
Fixed · RHSA-2024:1332
Red Hat Enterprise Linux 7
kpatch-patch
Fixed · RHSA-2024:1323
Red Hat Enterprise Linux 7.6 Advanced Update Support
kernel-0:3.10.0-957.111.1.el7
Fixed · RHSA-2024:0980
Red Hat Enterprise Linux 7.7 Advanced Update Support
kernel-0:3.10.0-1062.85.1.el7
Fixed · RHSA-2024:0999
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.18.1.el8_9
Fixed · RHSA-2024:0897
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.18.1.rt7.320.el8_9
Fixed · RHSA-2024:0881
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2024:0876
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.128.1.el8_2
Fixed · RHSA-2024:1268
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-0:4.18.0-193.128.1.el8_2
Fixed · RHSA-2024:1268
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-rt-0:4.18.0-193.128.1.rt13.179.el8_2
Fixed · RHSA-2024:1269
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kernel-0:4.18.0-193.128.1.el8_2
Fixed · RHSA-2024:1268
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2024:1278
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.120.1.el8_4
Fixed · RHSA-2024:0562
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-0:4.18.0-305.120.1.el8_4
Fixed · RHSA-2024:0562
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-rt-0:4.18.0-305.120.1.rt7.196.el8_4
Fixed · RHSA-2024:0563
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kernel-0:4.18.0-305.120.1.el8_4
Fixed · RHSA-2024:0562
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2024:0593
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 8.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:0378
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.43.1.el8_8
Fixed · RHSA-2024:0575
Red Hat Enterprise Linux 8.8 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:0554
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.13.1.el9_3
Fixed · RHSA-2023:7749
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.13.1.el9_3
Fixed · RHSA-2023:7749
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2023:7734
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.85.1.el9_0
Fixed · RHSA-2024:0432
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.85.1.rt21.156.el9_0
Fixed · RHSA-2024:0431
Red Hat Enterprise Linux 9.0 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:0386
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.48.1.el9_2
Fixed · RHSA-2024:0448
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.48.1.rt14.333.el9_2
Fixed · RHSA-2024:0439
Red Hat Enterprise Linux 9.2 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:0381
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.114.2.el7 | Fixed | RHSA-2024:1249 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.114.2.rt56.1266.el7 | Fixed | RHSA-2024:1332 |
| Red Hat Enterprise Linux 7 | kpatch-patch | Fixed | RHSA-2024:1323 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | kernel-0:3.10.0-957.111.1.el7 | Fixed | RHSA-2024:0980 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | kernel-0:3.10.0-1062.85.1.el7 | Fixed | RHSA-2024:0999 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.18.1.el8_9 | Fixed | RHSA-2024:0897 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.18.1.rt7.320.el8_9 | Fixed | RHSA-2024:0881 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2024:0876 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.128.1.el8_2 | Fixed | RHSA-2024:1268 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-0:4.18.0-193.128.1.el8_2 | Fixed | RHSA-2024:1268 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-rt-0:4.18.0-193.128.1.rt13.179.el8_2 | Fixed | RHSA-2024:1269 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kernel-0:4.18.0-193.128.1.el8_2 | Fixed | RHSA-2024:1268 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2024:1278 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.120.1.el8_4 | Fixed | RHSA-2024:0562 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-0:4.18.0-305.120.1.el8_4 | Fixed | RHSA-2024:0562 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-rt-0:4.18.0-305.120.1.rt7.196.el8_4 | Fixed | RHSA-2024:0563 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kernel-0:4.18.0-305.120.1.el8_4 | Fixed | RHSA-2024:0562 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2024:0593 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:0378 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.43.1.el8_8 | Fixed | RHSA-2024:0575 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:0554 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.13.1.el9_3 | Fixed | RHSA-2023:7749 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.13.1.el9_3 | Fixed | RHSA-2023:7749 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2023:7734 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.85.1.el9_0 | Fixed | RHSA-2024:0432 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.85.1.rt21.156.el9_0 | Fixed | RHSA-2024:0431 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:0386 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.48.1.el9_2 | Fixed | RHSA-2024:0448 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.48.1.rt14.333.el9_2 | Fixed | RHSA-2024:0439 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:0381 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is rated as Important because of its nature of exposure to the threat of impacting Confidentiality, Integrity and Availability by an attacker while being in an adjacent physical layer with no privilege required.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2023-45871 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2244723 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.3 Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-50137 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=bb5ed01cd2428cd25b1c88a3a9cba87055eb289f Mailing ListPatch
- https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-45871
- https://security.netapp.com/advisory/ntap-20231110-0001/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-45871
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-45871 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2244723 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.3 | Release Notes | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-50137 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=bb5ed01cd2428cd25b1c88a3a9cba87055eb289f | Mailing ListPatch | |
| https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-45871 | ||
| https://security.netapp.com/advisory/ntap-20231110-0001/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2023-45871 |
Change history (0)
No recorded changes yet.