CVE-2023-44466
Vulnerability Summary
Timeline
Description
An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.
CVSS Metrics
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 45.30%• Percentile: 99%
Techniques & Countermeasures
- CWE-120•Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Affected Systems
- debian•linux
< 6.1.52-1 | < 6.4.11-1 | < 6.4.11-1
- ubuntu•linux
< 5.15.0-86.96
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 5.15.0-1047.52
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1047.52~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
< 6.2.0-1015.15~22.04.1
- ubuntu•linux-azure
all | < 5.15.0-1049.56
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1049.56~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.2
< 6.2.0-1016.16~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | < 5.15.0-1049.56.1
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
< 6.2.0-1016.16~22.04.1.1
- ubuntu•linux-bluefield
all | < 5.15.0-1027.29
- ubuntu•linux-fips
all
- ubuntu•linux-gcp
all | < 5.15.0-1044.52
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1044.52~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.2
< 6.2.0-1018.20~22.04.1
- ubuntu•linux-gke
all | < 5.15.0-1044.49
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.15
all
- ubuntu•linux-gke-5.4
all
- ubuntu•linux-gkeop
< 5.15.0-1030.35
- ubuntu•linux-gkeop-5.15
< 5.15.0-1030.35~20.04.1
- ubuntu•linux-gkeop-5.4
all
- ubuntu•linux-hwe
all
- ubuntu•linux-hwe-5.11
all
- ubuntu•linux-hwe-5.13
all
- ubuntu•linux-hwe-5.15
< 5.15.0-86.96~20.04.1
- ubuntu•linux-hwe-5.19
all
- ubuntu•linux-hwe-5.8
all
- ubuntu•linux-hwe-6.2
< 6.2.0-36.37~22.04.1
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-ibm
< 5.15.0-1040.43
Showing first 50 affected entries in server-rendered view.
References (17)
- https://github.com/google/security-research/security/advisories/GHSA-jg27-jx6w-xwph
- https://www.spinics.net/lists/ceph-devel/msg57909.html
- https://github.com/torvalds/linux/commit/a282a2f10539dce2aa619e71e1817570d557fc97
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a282a2f10539dce2aa619e71e1817570d557fc97
- https://security.netapp.com/advisory/ntap-20231116-0003/
- https://ubuntu.com/security/CVE-2023-44466
- https://git.kernel.org/linus/a282a2f10539dce2aa619e71e1817570d557fc97
- https://ubuntu.com/security/notices/USN-6416-1
- https://ubuntu.com/security/notices/USN-6416-2
- https://ubuntu.com/security/notices/USN-6416-3
- https://ubuntu.com/security/notices/USN-6445-1
- https://ubuntu.com/security/notices/USN-6445-2
- https://ubuntu.com/security/notices/USN-6464-1
- https://ubuntu.com/security/notices/USN-6466-1
- https://ubuntu.com/security/notices/USN-6520-1
- https://www.cve.org/CVERecord?id=CVE-2023-44466
- https://security-tracker.debian.org/tracker/CVE-2023-44466