Vulnerability Description
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.15, < 4.19.265 |
| Redhat | Enterprise Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2023:6799Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:6813Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:7370Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:7379Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:7382Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:7389Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:7411Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:7418Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:7548Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:7549Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2023:7554Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2024:0340
- https://access.redhat.com/errata/RHSA-2024:0378
- https://access.redhat.com/errata/RHSA-2024:0412
- https://access.redhat.com/errata/RHSA-2024:0461
FAQ
What is CVE-2023-3812?
CVE-2023-3812 is a vulnerability with a CVSS score of 7.8 (HIGH). An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This...
How severe is CVE-2023-3812?
CVE-2023-3812 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3812?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux.