Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc Any unprivileged user can attach N_GSM0710 ldisc, but it requires CAP_NET_ADMIN to create a GSM network anyway. Require initial namespace CAP_NET_ADMIN to do that.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 4.19.312 |
| Debian | Debian Linux | 10.0 |
References
- https://git.kernel.org/stable/c/2b85977977cbd120591b23c2450e90a5806a7167Patch
- https://git.kernel.org/stable/c/2d154a54c58f9c8375bfbea9f7e51ba3bfb2e43aPatch
- https://git.kernel.org/stable/c/67c37756898a5a6b2941a13ae7260c89b54e0d88Patch
- https://git.kernel.org/stable/c/7a529c9023a197ab3bf09bb95df32a3813f7ba58Patch
- https://git.kernel.org/stable/c/7d303dee473ba3529d75b63491e9963342107bedPatch
- https://git.kernel.org/stable/c/ada28eb4b9561aab93942f3224a2e41d76fe57faPatch
- https://git.kernel.org/stable/c/2b85977977cbd120591b23c2450e90a5806a7167Patch
- https://git.kernel.org/stable/c/2d154a54c58f9c8375bfbea9f7e51ba3bfb2e43aPatch
- https://git.kernel.org/stable/c/67c37756898a5a6b2941a13ae7260c89b54e0d88Patch
- https://git.kernel.org/stable/c/7a529c9023a197ab3bf09bb95df32a3813f7ba58Patch
- https://git.kernel.org/stable/c/7d303dee473ba3529d75b63491e9963342107bedPatch
- https://git.kernel.org/stable/c/ada28eb4b9561aab93942f3224a2e41d76fe57faPatch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2023-52880?
CVE-2023-52880 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc Any unprivileged user can attach N_GSM0710 ldisc, but it requires CAP_...
How severe is CVE-2023-52880?
CVE-2023-52880 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-52880?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.