CVE-2023-6176

A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration, which could allow a local user to crash the system or escalate their privileges on the system.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:43

Type Values Removed Values Added
References
  • () http://packetstormsecurity.com/files/177029/Kernel-Live-Patch-Security-Notice-LSN-0100-1.html -
References () https://access.redhat.com/errata/RHSA-2024:2394 - () https://access.redhat.com/errata/RHSA-2024:2394 -
References () https://access.redhat.com/errata/RHSA-2024:2950 - () https://access.redhat.com/errata/RHSA-2024:2950 -
References () https://access.redhat.com/errata/RHSA-2024:3138 - () https://access.redhat.com/errata/RHSA-2024:3138 -
References () https://access.redhat.com/security/cve/CVE-2023-6176 - Third Party Advisory () https://access.redhat.com/security/cve/CVE-2023-6176 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2219359 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=2219359 - Issue Tracking
References () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cfaa80c91f6f99b9342b6557f0f0e1143e434066 - Mailing List, Patch () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cfaa80c91f6f99b9342b6557f0f0e1143e434066 - Mailing List, Patch

14 Sep 2024, 00:15

Type Values Removed Values Added
References
  • {'url': 'http://packetstormsecurity.com/files/177029/Kernel-Live-Patch-Security-Notice-LSN-0100-1.html', 'source': 'secalert@redhat.com'}

22 May 2024, 17:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2950 -
  • () https://access.redhat.com/errata/RHSA-2024:3138 -

30 Apr 2024, 14:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2394 -

08 Feb 2024, 16:15

Type Values Removed Values Added
References
  • () http://packetstormsecurity.com/files/177029/Kernel-Live-Patch-Security-Notice-LSN-0100-1.html -

01 Feb 2024, 18:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 4.7

23 Nov 2023, 03:42

Type Values Removed Values Added
CWE CWE-476
References () https://bugzilla.redhat.com/show_bug.cgi?id=2219359 - () https://bugzilla.redhat.com/show_bug.cgi?id=2219359 - Issue Tracking
References () https://access.redhat.com/security/cve/CVE-2023-6176 - () https://access.redhat.com/security/cve/CVE-2023-6176 - Third Party Advisory
References () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cfaa80c91f6f99b9342b6557f0f0e1143e434066 - () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cfaa80c91f6f99b9342b6557f0f0e1143e434066 - Mailing List, Patch
CPE cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Redhat enterprise Linux
Linux
Redhat
Linux linux Kernel

16 Nov 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-16 18:15

Updated : 2024-11-21 08:43


NVD link : CVE-2023-6176

Mitre link : CVE-2023-6176

CVE.ORG link : CVE-2023-6176


JSON object : View

Products Affected

redhat

  • enterprise_linux

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference