CVE-2023-42752

An integer overflow flaw was found in the Linux kernel. This issue leads to the kernel allocating `skb_shared_info` in the userspace, which is exploitable in systems without SMAP protection since `skb_shared_info` contains references to function pointers.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

29 Nov 2023, 15:15

Type Values Removed Values Added
References
  • () http://packetstormsecurity.com/files/175963/Kernel-Live-Patch-Security-Notice-LSN-0099-1.html -

18 Oct 2023, 19:51

Type Values Removed Values Added
CWE CWE-190
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=915d975b2ffa - (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=915d975b2ffa - Mailing List, Patch
References (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=c3b704d4a4a2 - (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=c3b704d4a4a2 - Mailing List, Patch
References (MISC) https://access.redhat.com/security/cve/CVE-2023-42752 - (MISC) https://access.redhat.com/security/cve/CVE-2023-42752 - Third Party Advisory
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2239828 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2239828 - Issue Tracking, Third Party Advisory
First Time Linux
Linux linux Kernel

13 Oct 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-13 02:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-42752

Mitre link : CVE-2023-42752

CVE.ORG link : CVE-2023-42752


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-190

Integer Overflow or Wraparound