tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc
Published May 24, 2024
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
Any unprivileged user can attach N_GSM0710 ldisc, but it requires CAP_NET_ADMIN to create a GSM network anyway.
Require initial namespace CAP_NET_ADMIN to do that.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.35StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.35
- Version 4.19.312StatusunaffectedConstraints<=4.19.*
- Version 5.10.215StatusunaffectedConstraints<=5.10.*
- Version 5.15.155StatusunaffectedConstraints<=5.15.*
- Version 5.4.274StatusunaffectedConstraints<=5.4.*
- Version 6.1.86StatusunaffectedConstraints<=6.1.*
- Version 6.6StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
Configuration 1
- < 4.19.312
- ≥ 4.20 · < 5.4.274
- ≥ 5.5 · < 5.10.215
- ≥ 5.11 · < 5.15.155
- ≥ 5.16 · < 6.1.86
- ≥ 6.2 · < 6.6
Configuration 2
- 10.0
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.33.1.el9_4
Fixed · RHSA-2024:5928
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.33.1.el9_4
Fixed · RHSA-2024:5928
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.84.1.el9_2
Fixed · RHSA-2024:6744
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.84.1.rt14.369.el9_2
Fixed · RHSA-2024:6745
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.33.1.el9_4 | Fixed | RHSA-2024:5928 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.33.1.el9_4 | Fixed | RHSA-2024:5928 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.84.1.el9_2 | Fixed | RHSA-2024:6744 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.84.1.rt14.369.el9_2 | Fixed | RHSA-2024:6745 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-52880 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2283468 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59593 Advisory
- https://git.kernel.org/stable/c/2b85977977cbd120591b23c2450e90a5806a7167 Patch
- https://git.kernel.org/stable/c/2d154a54c58f9c8375bfbea9f7e51ba3bfb2e43a Patch
- https://git.kernel.org/stable/c/67c37756898a5a6b2941a13ae7260c89b54e0d88 Patch
- https://git.kernel.org/stable/c/7a529c9023a197ab3bf09bb95df32a3813f7ba58 Patch
- https://git.kernel.org/stable/c/7d303dee473ba3529d75b63491e9963342107bed Patch
- https://git.kernel.org/stable/c/ada28eb4b9561aab93942f3224a2e41d76fe57fa Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html Mailing ListThird Party Advisory
- https://lore.kernel.org/linux-cve-announce/2024052422-CVE-2023-52880-d2ff@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52880
- https://www.cve.org/CVERecord?id=CVE-2023-52880
Change history (0)
No recorded changes yet.