cbcvebase.
CVE-2023-35788
published 2023-06-16

CVE-2023-35788: An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.53%
41.4th percentile
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 5.4.0-153.1705.4.0-153.170
linuxlinux_kernel>= 0 < 5.15.0-76.835.15.0-76.83
linuxlinux_kernel>= 0 < 4.4.0-243.2774.4.0-243.277
linuxlinux_kernel>= 0 < 5.4.0-155.1725.4.0-155.172
linuxlinux_kernel>= 0 < 5.15.0-78.855.15.0-78.85
linuxlinux_kernel>= 4.19 < 4.19.2854.19.285
linuxlinux_kernel>= 4.20 < 5.4.2465.4.246
linuxlinux_kernel>= 5.11 < 5.15.1165.15.116
linuxlinux_kernel>= 5.16 < 6.1.336.1.33
linuxlinux_kernel>= 5.5 < 5.10.1835.10.183
linuxlinux_kernel>= 6.2 < 6.3.76.3.7
msrccbl2_kernel_5.15.116.1-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.