7.5

CVE-2023-46838

Linux: netback processing of zero-length transmit fragment

Transmit requests in Xen's virtual network protocol can consist of
multiple parts.  While not really useful, except for the initial part
any of them may be of zero length, i.e. carry no data at all.  Besides a
certain initial portion of the to be transferred data, these parts are
directly translated into what Linux calls SKB fragments.  Such converted
request parts can, when for a particular SKB they are all of length
zero, lead to a de-reference of NULL in core networking code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.14 < 4.19.306
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.268
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.209
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.148
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.75
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.14
Linux ≫ Linux Kernel Version >= 6.7 < 6.7.2
Fedoraproject ≫ Fedora Version 38
Fedoraproject ≫ Fedora Version 39
Debian ≫ Debian Linux Version 10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.18% 0.635
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGEKT4DKSDXDS34EL7M4UVJMMPH7Z3ZZ/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZFYW6R64GPLUOXSQBJI3JBUX3HGLAYPP/
Mailing List
https://xenbits.xenproject.org/xsa/advisory-448.html
Patch
Third Party Advisory
http://xenbits.xen.org/xsa/advisory-448.html