The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled.
We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3508-1 | linux security update |
Debian DLA |
DLA-3623-1 | linux-5.10 security update |
Debian DSA |
DSA-5448-1 | linux security update |
Debian DSA |
DSA-5480-1 | linux security update |
EUVD |
EUVD-2023-43778 | A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e. |
Ubuntu USN |
USN-6231-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6246-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6250-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6251-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6252-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6254-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6255-1 | Linux kernel (Intel IoTG) vulnerabilities |
Ubuntu USN |
USN-6260-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6261-1 | Linux kernel (IoT) vulnerabilities |
Ubuntu USN |
USN-6385-1 | Linux kernel (OEM) vulnerabilities |
Wed, 05 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e. | A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e. |
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-03-05T18:55:25.596Z
Reserved: 2023-06-03T22:31:04.130Z
Link: CVE-2023-3090
Updated: 2024-08-02T06:41:04.144Z
Status : Modified
Published: 2023-06-28T20:15:09.693
Modified: 2025-02-13T17:16:55.200
Link: CVE-2023-3090
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN