CVE-2023-1076

Aliases:UBUNTU-CVE-2023-1076DEBIAN-CVE-2023-1076CGA-2274-p3f8-fphmCGA-2447-8qvh-cccjCGA-27pp-hjr2-gg72CGA-295f-cm67-h3fvCGA-2cpr-pw42-mwg2CGA-2g5v-4923-wcm3CGA-2p3c-6529-rj4vCGA-2rm9-9724-xmpwCGA-2rpg-vw56-jfgpCGA-2w6c-m3qj-5jc8CGA-3279-6www-v9mvCGA-39j8-fh53-pp8xCGA-3cw6-8799-vrwmCGA-3q27-wrvf-3fpwCGA-3qr5-rc5q-q26xCGA-3w9j-mg47-5gmwCGA-3xr9-6pcj-wfj5CGA-4v3g-g2hm-fwmxCGA-4xmv-6ch9-f557CGA-5253-32rm-h7xxCGA-53jw-xg2w-w5jfCGA-552w-xh2x-f293CGA-56qc-667p-w4w4CGA-583f-w267-f3q3CGA-5p74-x67h-c7m2CGA-5pwh-rfj4-4w93CGA-5qfr-rh65-m7x8CGA-626p-2x34-rghxCGA-696q-5w6r-p2j3CGA-69pm-4cjp-gfg4CGA-6cj3-gwjf-xmqhCGA-6h4g-6vhp-f856CGA-6hp7-r839-m2gcCGA-6hv9-98vp-hp45CGA-6hvg-v243-77phCGA-6xrm-phf6-6vg2CGA-7j6j-q89x-2jm7CGA-7mpf-vj9c-xjrqCGA-7p2c-xm2f-9c98CGA-7rjg-9hj3-h9cqCGA-7rmh-9rm7-67wmCGA-7vg5-7rv2-g365CGA-86qg-jqgj-3469CGA-8896-965m-phxfCGA-8f3v-3crx-4f7xCGA-93w8-g7f9-pcj4CGA-93x9-x568-f7ghCGA-95gc-mfpr-hwm5CGA-95pm-jvjg-x6qpCGA-9f63-gw7f-5pwqCGA-9rv3-2hqg-qg9mCGA-c769-mq5r-r86mCGA-cc28-r698-fc24CGA-chc3-f5qq-4v9pCGA-cj5m-4c9v-5fv5CGA-cxh3-m4fh-36w4CGA-f7v6-x4hh-fxxjCGA-fgr8-9w6h-r444CGA-frjv-9c58-342hCGA-g5r4-3xwq-p2ppCGA-g7fm-xhjj-92fcCGA-gj45-p8h2-5mmjCGA-gr93-ffmc-p7c8CGA-gw2q-3m2f-47gjCGA-gw8w-4g3m-fcf6CGA-gw8w-jc59-c74gCGA-gwx4-4rc9-wqh5CGA-h262-vv2m-73ffCGA-hff5-cp7m-98cwCGA-hgh9-928m-xjc4CGA-hgr2-mcj8-2m34CGA-hm65-p86p-6fjfCGA-hvr2-292p-9579CGA-j57f-2p24-wmccCGA-jfc9-48rq-rxp4CGA-jh9j-jf3v-fh73CGA-jmm4-8pj8-q7hqCGA-jqrc-gfjp-5f6fCGA-jrg4-cx58-6v95CGA-m498-3f8r-694mCGA-m555-hw3c-37g3CGA-m6x2-fhpv-hhr8CGA-m997-r3vm-33gmCGA-mcc5-22hf-g36rCGA-mhm5-cccc-ggh8CGA-mx4r-8rxr-6h4rCGA-mxc9-2qqm-84c9CGA-p659-2r2x-hq37CGA-p779-rhc6-7g39CGA-p833-pfhw-9w8wCGA-pjq6-xxpm-cr7qCGA-qv7h-r33j-r2q3CGA-qv98-4422-83cxCGA-qw85-592r-5jw8CGA-r2g7-r6p6-2hwfCGA-r958-2cf2-r7c8CGA-rf5q-r9gh-m458CGA-rh78-vxh5-25f7CGA-rw5f-6w28-qph9CGA-v8xf-3f6q-vhx3CGA-vrmr-xrpr-4m7mCGA-vwmf-7c3g-733qCGA-w93c-wfvc-j8cpCGA-whpx-p393-9rxjCGA-whrq-gmq2-v9vpCGA-wqjm-7hr8-7qcqCGA-wvcc-j53m-xvchCGA-wvpc-6799-43g3CGA-wxp3-6rwq-pp2fCGA-wxxg-49g9-qpq6CGA-x5g4-pw89-jmq4CGA-xfrx-xcpx-pg98CGA-xhw9-3cmj-pm9gCGA-xvj7-7mx3-3354CGA-rv6p-993f-xvmvCGA-wp68-v5mv-ph97CGA-3w33-xx4p-ghmcCGA-42jj-qgv3-whpwCGA-4qpr-w374-247rCGA-87cc-m6q3-fm7rCGA-978f-9xp8-mwppCGA-c42f-5c72-wvp4CGA-c9wv-9624-7wvgCGA-cvc5-jx42-vvwvCGA-gp9j-8mg4-6p44CGA-jhj4-3mg7-7jpxCGA-mmq8-hxrr-wfj6CGA-p4vg-cp6g-95fcCGA-v8xv-7h6q-f9x2CGA-wjrg-9494-4qv4CGA-8m97-2j7w-xpqvCGA-2x4h-vrmx-5v36CGA-jr9w-ghw9-5xc3CGA-qcjp-fhj9-c6rpCGA-qpc9-fcxh-7r7hCGA-w4jw-2hrq-xvwhCGA-j28g-4x6c-x59qCGA-8596-mpg2-346gCGA-9wcw-885j-p36gCGA-x853-vjjf-vgp2
Advisory lineage Upstream: 0 Downstream: 33
Modified
Published: 27 Mar 2023, 00:00
Last modified:24 Feb 2025, 17:04

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.26% LOW
0% probability +0.25%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Mar 2023, 00:00
Published
Vulnerability first disclosed
24 Feb 2025, 17:04
Last Modified
Vulnerability information updated

Description

A flaw was found in the Linux Kernel. The tun/tap sockets have their socket UID hardcoded to 0 due to a type confusion in their initialization function. While it will be often correct, as tuntap devices require CAP_NET_ADMIN, it may not always be the case, e.g., a non-root user only having that capability. This would make tun/tap sockets being incorrectly treated in filtering/routing decisions, possibly bypassing network filters.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.26% Percentile: 18%

Techniques & Countermeasures

  • CWE-791Incomplete Filtering of Special Elements

    The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

  • CWE-843Access of Resource Using Incompatible Type ('Type Confusion')

    The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Affected Systems

  • chainguardhyperv-daemons-6.18

    < 0

  • chainguardhyperv-daemons-generic

    < 0

  • chainguardlinux-aws-6.12

    < 6.12.65-r0 | < 0

  • chainguardlinux-aws-6.12-boot-installed

    < 0

  • chainguardlinux-aws-6.12-fips-boot-installed

    < 0

  • chainguardlinux-aws-6.12-headers

    < 0

  • chainguardlinux-aws-6.12-modules

    < 0

  • chainguardlinux-aws-6.18

    < 0 | < 6.18.10-r0

  • chainguardlinux-aws-6.18-boot-installed

    < 0

  • chainguardlinux-aws-6.18-fips-boot-installed

    < 0

  • chainguardlinux-aws-6.18-headers

    < 0

  • chainguardlinux-aws-6.18-modules

    < 0

  • chainguardlinux-aws-generic

    < 6.18.5-r0 | < 0

  • chainguardlinux-aws-generic-boot-installed

    < 0

  • chainguardlinux-aws-generic-fips-boot-installed

    < 0

  • chainguardlinux-aws-generic-headers

    < 0

  • chainguardlinux-aws-generic-modules

    < 0

  • chainguardlinux-azure-6.12

    < 6.12.65-r1 | < 0

  • chainguardlinux-azure-6.18

    < 0

  • chainguardlinux-azure-6.18-boot-installed

    < 0

  • chainguardlinux-azure-6.18-fips-boot-installed

    < 0

  • chainguardlinux-azure-6.18-headers

    < 0

  • chainguardlinux-azure-6.18-modules

    < 0

  • chainguardlinux-azure-generic

    < 6.18.5-r0 | < 0

  • chainguardlinux-azure-generic-boot-installed

    < 0

  • chainguardlinux-azure-generic-fips-boot-installed

    < 0

  • chainguardlinux-azure-generic-headers

    < 0

  • chainguardlinux-azure-generic-modules

    < 0

  • chainguardlinux-desktop-6.18

    all

  • chainguardlinux-desktop-6.18-bootc

    all

  • chainguardlinux-desktop-6.18-bootc-boot-installed

    all

  • chainguardlinux-desktop-6.18-headers

    all

  • chainguardlinux-desktop-6.18-modules

    all

  • chainguardlinux-desktop-7.2

    all

  • chainguardlinux-desktop-7.2-bootc

    all

  • chainguardlinux-desktop-7.2-bootc-boot-installed

    all

  • chainguardlinux-desktop-7.2-headers

    all

  • chainguardlinux-desktop-7.2-modules

    all

  • chainguardlinux-firecracker-6.18

    all

  • chainguardlinux-gcp-6.12

    < 6.12.65-r0 | < 0

  • chainguardlinux-gcp-6.18

    < 6.18.10-r0 | < 0

  • chainguardlinux-gcp-6.18-boot-installed

    < 0

  • chainguardlinux-gcp-6.18-fips-boot-installed

    < 0

  • chainguardlinux-gcp-6.18-headers

    < 0

  • chainguardlinux-gcp-6.18-modules

    < 0

  • chainguardlinux-gcp-generic

    < 0 | < 6.18.5-r0

  • chainguardlinux-gcp-generic-boot-installed

    < 0

  • chainguardlinux-gcp-generic-fips-boot-installed

    < 0

  • chainguardlinux-gcp-generic-headers

    < 0

  • chainguardlinux-gcp-generic-modules

    < 0

Showing first 50 affected entries in server-rendered view.

References (18)