cbcvebase.
CVE-2023-3772
published 2023-07-25

CVE-2023-3772: A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN…

medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < ed1cba039309c80b49719fcff3e3d7cdddb73d96ed1cba039309c80b49719fcff3e3d7cdddb73d96
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 44f69c96f8a147413c23c68cda4d6fb5e23137cd44f69c96f8a147413c23c68cda4d6fb5e23137cd
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 8046beb890ebc83c5820188c650073e1c6066e678046beb890ebc83c5820188c650073e1c6066e67
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < bd30aa9c7febb6e709670cd5154194189ca3b7b5bd30aa9c7febb6e709670cd5154194189ca3b7b5
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 075448a2eb753f813fe873cfa52853e9fef8eedb075448a2eb753f813fe873cfa52853e9fef8eedb
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 87b655f4936b6fc01f3658aa88a22c923b379ebd87b655f4936b6fc01f3658aa88a22c923b379ebd
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 53df4be4f5221e90dc7aa9ce745a9a21bb7024f453df4be4f5221e90dc7aa9ce745a9a21bb7024f4
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 00374d9b6d9f932802b55181be9831aa948e5b7c00374d9b6d9f932802b55181be9831aa948e5b7c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.13-16.4.13-1
linuxlinux_kernel>= 0 < 6.4.13-16.4.13-1
linuxlinux_kernel>= 0 < 5.4.0-166.1835.4.0-166.183
linuxlinux_kernel>= 0 < 5.15.0-88.985.15.0-88.98
linuxlinux_kernel>= 0 < 4.4.0-246.2804.4.0-246.280
linuxlinux_kernel>= 0 < 4.15.0-219.2304.15.0-219.230
linuxlinux_kernel>= 2.6.39 < 4.14.3244.14.324
linuxlinux_kernel>= 4.15 < 4.19.2934.19.293
linuxlinux_kernel>= 4.20 < 5.4.2555.4.255
linuxlinux_kernel>= 5.11 < 5.15.1285.15.128

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv9.8CRITICAL