CVE-2023-28327NULL Pointer Dereference in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateApr 20

Description

A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Debianlinux/linux_kernel< 5.10.162-1+3
CVEListV5linux/linux_kernelLinux

Also affects: Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-gpc7-6g78-vfxw: A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag2023-04-20
OSV
CVE-2023-28327: A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag2023-04-19
CVEList
CVE-2023-28327: A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag2023-04-19

📋Vendor Advisories

4
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Golang Go) — CVE-2022-283272023-04-15
Microsoft
A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk leading to a NULL pointer. This f2023-04-11
Debian
CVE-2023-28327: linux - A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag....2023
Red Hat
kernel: denial of service problem in net/unix/diag.c2022-11-22
CVE-2023-28327 — NULL Pointer Dereference in Kernel | cvebase