Vulnerability Description
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.7, < 5.10.184 |
| Redhat | Enterprise Linux | 9.0 |
| Fedoraproject | Fedora | 38 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2023/05/17/8Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/17/9Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/18/1Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/19/1Mailing List
- https://bugzilla.redhat.com/show_bug.cgi?id=2196292Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00001.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230622-0001/Mailing ListThird Party Advisory
- https://www.debian.org/security/2023/dsa-5448Third Party AdvisoryVDB Entry
- https://www.debian.org/security/2023/dsa-5453Third Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-23-547/Third Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2023/05/17/8Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/17/9Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/18/1Mailing List
- http://www.openwall.com/lists/oss-security/2023/05/19/1Mailing List
- https://bugzilla.redhat.com/show_bug.cgi?id=2196292Issue TrackingThird Party Advisory
FAQ
What is CVE-2023-2156?
CVE-2023-2156 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to a...
How severe is CVE-2023-2156?
CVE-2023-2156 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2156?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux, Fedoraproject Fedora, Debian Debian Linux.