Kernel: null pointer dereference in nvmet_tcp_execute_request
Published Feb 7, 2024
7.5
HIGHCVSS 3.1
EPSS 1.55%
Description
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
Configuration 1
- n/a
Configuration 2
- 8.6
- 9.2
- 8.6_ppc64le
- 9.2_ppc64le
- 8.6_aarch64
- 9.2_aarch64
- 9.2_s390x
- 8.0
- 9.0
- 8.6
- 9.2
- 8.6_aarch64
- 9.2_aarch64
- 8.6_s390x
- 9.2_s390x
- 8.6_ppc64le
- 9.2_ppc64le
- 9.2
- 9.2
- 8.6
- 9.2
- 8.6_ppc64le
- 9.2_ppc64le
- 8.6
Configuration 3
- 4.0
Running on/with
- 8.0
No data.
RHOL-5.8-RHEL-9
openshift-logging/cluster-logging-operator-bundle:v5.8.6-22
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/cluster-logging-rhel9-operator:v5.8.6-11
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/elasticsearch-operator-bundle:v5.8.6-19
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/elasticsearch-proxy-rhel9:v1.0.0-479
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/elasticsearch-rhel9-operator:v5.8.6-7
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/elasticsearch6-rhel9:v6.8.1-407
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/eventrouter-rhel9:v0.4.0-247
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/fluentd-rhel9:v5.8.6-5
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-227
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/logging-curator5-rhel9:v5.8.1-470
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/logging-loki-rhel9:v2.9.6-14
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/logging-view-plugin-rhel9:v5.8.6-2
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/loki-operator-bundle:v5.8.6-24
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/loki-rhel9-operator:v5.8.6-10
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/lokistack-gateway-rhel9:v0.1.0-525
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/opa-openshift-rhel9:v0.1.0-224
Fixed · RHSA-2024:2094
RHOL-5.8-RHEL-9
openshift-logging/vector-rhel9:v0.28.1-56
Fixed · RHSA-2024:2094
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.18.1.el8_9
Fixed · RHSA-2024:0897
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.18.1.rt7.320.el8_9
Fixed · RHSA-2024:0881
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.91.1.el8_6
Fixed · RHSA-2024:0724
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.58.1.el8_8
Fixed · RHSA-2024:3810
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.24.1.el9_3
Fixed · RHSA-2024:1248
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.24.1.el9_3
Fixed · RHSA-2024:1248
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.52.1.el9_2
Fixed · RHSA-2024:0723
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.52.1.rt14.337.el9_2
Fixed · RHSA-2024:0725
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.91.1.el8_6
Fixed · RHSA-2024:0724
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHOL-5.8-RHEL-9 | openshift-logging/cluster-logging-operator-bundle:v5.8.6-22 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/cluster-logging-rhel9-operator:v5.8.6-11 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/elasticsearch-operator-bundle:v5.8.6-19 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/elasticsearch-proxy-rhel9:v1.0.0-479 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/elasticsearch-rhel9-operator:v5.8.6-7 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/elasticsearch6-rhel9:v6.8.1-407 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/eventrouter-rhel9:v0.4.0-247 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/fluentd-rhel9:v5.8.6-5 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-227 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/logging-curator5-rhel9:v5.8.1-470 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/logging-loki-rhel9:v2.9.6-14 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/logging-view-plugin-rhel9:v5.8.6-2 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/loki-operator-bundle:v5.8.6-24 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/loki-rhel9-operator:v5.8.6-10 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/lokistack-gateway-rhel9:v0.1.0-525 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/opa-openshift-rhel9:v0.1.0-224 | Fixed | RHSA-2024:2094 |
| RHOL-5.8-RHEL-9 | openshift-logging/vector-rhel9:v0.28.1-56 | Fixed | RHSA-2024:2094 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.18.1.el8_9 | Fixed | RHSA-2024:0897 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.18.1.rt7.320.el8_9 | Fixed | RHSA-2024:0881 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.91.1.el8_6 | Fixed | RHSA-2024:0724 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.58.1.el8_8 | Fixed | RHSA-2024:3810 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.24.1.el9_3 | Fixed | RHSA-2024:1248 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.24.1.el9_3 | Fixed | RHSA-2024:1248 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.52.1.el9_2 | Fixed | RHSA-2024:0723 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.52.1.rt14.337.el9_2 | Fixed | RHSA-2024:0725 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.91.1.el8_6 | Fixed | RHSA-2024:0724 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, prevent module nvmet-tcp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
Red Hat statement
Red Hat Enterprise Linux 6 and 7 are not affected by this issue as it doesn't ship the related NVMe driver code.
Red Hat mitigation
To mitigate this issue, prevent module nvmet-tcp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
References (15)
- https://access.redhat.com/errata/RHSA-2024:0723 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0724 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0725 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0881 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0897 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1248 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2094 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:3810 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6535 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2254053 issue-trackingx_refsource_REDHATIssue Tracking
- https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZFYW6R64GPLUOXSQBJI3JBUX3HGLAYPP/
- https://nvd.nist.gov/vuln/detail/CVE-2023-6535
- https://security.netapp.com/advisory/ntap-20240415-0003/
- https://www.cve.org/CVERecord?id=CVE-2023-6535
Change history (0)
No recorded changes yet.