CVE-2023-2156
Vulnerability Summary
Timeline
Description
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 6.13%• Percentile: 93%
Techniques & Countermeasures
- CWE-617•Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Affected Systems
- debian•linux
< 5.10.179-2 | < 6.1.37-1 | < 6.3.11-1 | < 6.3.11-1
- ubuntu•linux
< 5.15.0-86.96
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 5.15.0-1047.52
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1047.52~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
< 6.2.0-1013.13~22.04.1
- ubuntu•linux-azure
all | < 5.15.0-1049.56
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1049.56~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.2
< 6.2.0-1014.14~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
< 5.15.0-1049.56.1
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
< 6.2.0-1014.14~22.04.1.1
- ubuntu•linux-bluefield
all | < 5.15.0-1027.29
- ubuntu•linux-fips
all
- ubuntu•linux-gcp
all | < 5.15.0-1044.52
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1044.52~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.2
< 6.2.0-1016.18~22.04.1
- ubuntu•linux-gke
< 5.15.0-1044.49
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.15
all
- ubuntu•linux-gke-5.4
all
- ubuntu•linux-gkeop
< 5.15.0-1030.35
- ubuntu•linux-gkeop-5.15
< 5.15.0-1030.35~20.04.1
- ubuntu•linux-gkeop-5.4
all
- ubuntu•linux-hwe
all
- ubuntu•linux-hwe-5.11
all
- ubuntu•linux-hwe-5.13
all
- ubuntu•linux-hwe-5.15
< 5.15.0-86.96~20.04.1
- ubuntu•linux-hwe-5.19
all
- ubuntu•linux-hwe-5.8
all
- ubuntu•linux-hwe-6.2
< 6.2.0-34.34~22.04.1
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-ibm
< 5.15.0-1040.43
Showing first 50 affected entries in server-rendered view.
References (22)
- https://www.zerodayinitiative.com/advisories/ZDI-23-547/
- https://bugzilla.redhat.com/show_bug.cgi?id=2196292
- http://www.openwall.com/lists/oss-security/2023/05/17/8
- http://www.openwall.com/lists/oss-security/2023/05/17/9
- http://www.openwall.com/lists/oss-security/2023/05/18/1
- http://www.openwall.com/lists/oss-security/2023/05/19/1
- https://security.netapp.com/advisory/ntap-20230622-0001/
- https://www.debian.org/security/2023/dsa-5448
- https://www.debian.org/security/2023/dsa-5453
- https://lists.debian.org/debian-lts-announce/2023/08/msg00001.html
- https://ubuntu.com/security/CVE-2023-2156
- https://www.interruptlabs.co.uk/articles/linux-ipv6-route-of-death
- https://ubuntu.com/security/notices/USN-6173-1
- https://ubuntu.com/security/notices/USN-6412-1
- https://ubuntu.com/security/notices/USN-6416-1
- https://ubuntu.com/security/notices/USN-6416-2
- https://ubuntu.com/security/notices/USN-6416-3
- https://ubuntu.com/security/notices/USN-6445-1
- https://ubuntu.com/security/notices/USN-6445-2
- https://ubuntu.com/security/notices/USN-6466-1
- https://www.cve.org/CVERecord?id=CVE-2023-2156
- https://security-tracker.debian.org/tracker/CVE-2023-2156