cbcvebase.
CVE-2023-2006
published 2023-04-24

CVE-2023-2006: A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper…

high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.12-1 (bookworm)linux 6.0.12-1 (bookworm)
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 5.10 < 5.10.1575.10.157
linuxlinux_kernel>= 5.11 < 5.15.815.15.81
linuxlinux_kernel>= 5.16 < 6.0.116.0.11
msrccbl2_kernel_5.15.111.1-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_kernel_5.10.181.1-1_on_cbl_mariner_1.0
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH