CVE-2023-4459

Aliases:UBUNTU-CVE-2023-4459DEBIAN-CVE-2023-4459
Advisory lineage Upstream: 0 Downstream: 28
Modified
Published: 21 Aug 2023, 18:49
Last modified:15 Nov 2025, 08:17

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.25% LOW
0% probability +0.24%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Aug 2023, 18:49
Published
Vulnerability first disclosed
15 Nov 2025, 08:17
Last Modified
Vulnerability information updated

Description

A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel. This issue may allow a local attacker with normal user privilege to cause a denial of service due to a missing sanity check during cleanup.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.25% Percentile: 17%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • debianlinux

    < 5.10.120-1 | < 5.17.11-1 | < 5.17.11-1 | < 5.17.11-1

  • ubuntulinux

    all | < 4.4.0-245.279 | < 4.15.0-191.202 | < 5.4.0-126.142 | < 5.15.0-47.51

  • ubuntulinux-aws

    < 4.4.0-1123.129 | < 4.4.0-1161.176 | < 4.15.0-1139.150 | < 5.4.0-1085.92 | < 5.15.0-1019.23

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1019.23~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1085.92~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-fips

    < 4.15.0-2078.83 | all | < 5.4.0-1085.92+fips1

  • ubuntulinux-aws-hwe

    < 4.15.0-1139.150~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1149.164~14.04.1 | < 4.15.0-1149.164~16.04.1 | all | < 5.4.0-1091.96 | < 5.15.0-1019.24

  • ubuntulinux-azure-4.15

    < 4.15.0-1149.164

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1019.24~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1091.96~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2059.65 | all | < 5.4.0-1091.96+fips1

  • ubuntulinux-bluefield

    all | < 5.4.0-1046.51

  • ubuntulinux-fips

    < 4.4.0-1093.100 | all | < 4.15.0-1096.107 | < 5.4.0-1061.69

  • ubuntulinux-gcp

    < 4.15.0-1134.150~16.04.2 | all | < 5.4.0-1089.97 | < 5.15.0-1017.23

  • ubuntulinux-gcp-4.15

    < 4.15.0-1134.150

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    < 5.15.0-1017.23~20.04.2

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1089.97~18.04.1

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-fips

    < 4.15.0-2043.48 | all | < 5.4.0-1089.97+fips1

  • ubuntulinux-gke

    all | < 5.15.0-1015.18

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.15

    all

  • ubuntulinux-gke-5.4

    all

  • ubuntulinux-gkeop

    < 5.4.0-1053.56 | < 5.15.0-1002.4

  • ubuntulinux-gkeop-5.4

    all

  • ubuntulinux-hwe

    < 4.15.0-191.202~16.04.1 | all

  • ubuntulinux-hwe-5.11

    all

  • ubuntulinux-hwe-5.13

    all

  • ubuntulinux-hwe-5.15

    < 5.15.0-48.54~20.04.1

  • ubuntulinux-hwe-5.4

    < 5.4.0-126.142~18.04.1

  • ubuntulinux-hwe-5.8

    all

  • ubuntulinux-hwe-edge

    all | all

Showing first 50 affected entries in server-rendered view.

References (15)