cbcvebase.
CVE-2023-1206
published 2023-06-30

CVE-2023-1206: A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack…

medium5.7CVSS 3.1
AVAACLPRLUINSUCNINAH
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
fedoraprojectfedora
linuxlinux_kernel< 6.56.5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 5.4.0-164.1815.4.0-164.181
linuxlinux_kernel>= 0 < 5.15.0-86.965.15.0-86.96
linuxlinux_kernel>= 0 < 3.13.0-194.2453.13.0-194.245
linuxlinux_kernel>= 0 < 4.4.0-246.2804.4.0-246.280
linuxlinux_kernel>= 0 < 4.15.0-219.2304.15.0-219.230
msrccbl2_kernel_5.15.126.1-1_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux
ubuntulinux-intel-iotg-5.15

CVSS provenance

nvdv3.15.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH