CVE-2023-3812
published 2023-07-24CVE-2023-3812: An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big)…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.9th percentile
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.8-1 (bookworm) | linux 6.0.8-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 4.15 < 4.19.265 | 4.19.265 |
| linux | linux_kernel | >= 4.20 < 5.4.224 | 5.4.224 |
| linux | linux_kernel | >= 5.11 < 5.15.78 | 5.15.78 |
| linux | linux_kernel | >= 5.16 < 6.0.8 | 6.0.8 |
| linux | linux_kernel | >= 5.5 < 5.10.154 | 5.10.154 |
| msrc | cbl2_kernel_5.15.126.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v4mv-7g6h-5vh8: An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big)
ghsa_unreviewed·2023-07-24
CVE-2023-3812 [HIGH] CWE-416 GHSA-v4mv-7g6h-5vh8: An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big)
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
OSV
CVE-2023-3812: An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big)
osv·2023-07-24·CVSS 7.8
CVE-2023-3812 [HIGH] CVE-2023-3812: An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big)
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Microsoft
Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags
vendor_msrc·2023-07-11·CVSS 7.8
CVE-2023-3812 [HIGH] CWE-787 Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags
Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Re
Debian
CVE-2023-3812: linux - An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP devi...
vendor_debian·2023·CVSS 7.8
CVE-2023-3812 [HIGH] CVE-2023-3812: linux - An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP devi...
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Scope: local
bookworm: resolved (fixed in 6.0.8-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.8-1)
sid: resolved (fixed in 6.0.8-1)
trixie: resolved (fixed in 6.0.8-1)
Red Hat
kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags
vendor_redhat·2022-10-22·CVSS 7.8
CVE-2023-3812 [HIGH] CWE-787 kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags
kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Mitigation: To mitigate this issue, prevent the tun module from being loaded. Please see https://access.redhat.com/solutions/4127
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2023:6799https://access.redhat.com/errata/RHSA-2023:6813https://access.redhat.com/errata/RHSA-2023:7370https://access.redhat.com/errata/RHSA-2023:7379https://access.redhat.com/errata/RHSA-2023:7382https://access.redhat.com/errata/RHSA-2023:7389https://access.redhat.com/errata/RHSA-2023:7411https://access.redhat.com/errata/RHSA-2023:7418https://access.redhat.com/errata/RHSA-2023:7548https://access.redhat.com/errata/RHSA-2023:7549https://access.redhat.com/errata/RHSA-2023:7554https://access.redhat.com/errata/RHSA-2024:0340https://access.redhat.com/errata/RHSA-2024:0378https://access.redhat.com/errata/RHSA-2024:0412https://access.redhat.com/errata/RHSA-2024:0461https://access.redhat.com/errata/RHSA-2024:0554https://access.redhat.com/errata/RHSA-2024:0562https://access.redhat.com/errata/RHSA-2024:0563https://access.redhat.com/errata/RHSA-2024:0575https://access.redhat.com/errata/RHSA-2024:0593https://access.redhat.com/errata/RHSA-2024:1961https://access.redhat.com/errata/RHSA-2024:2006https://access.redhat.com/errata/RHSA-2024:2008https://access.redhat.com/security/cve/CVE-2023-3812https://bugzilla.redhat.com/show_bug.cgi?id=2224048https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=363a5328f4b0https://access.redhat.com/errata/RHSA-2023:6799https://access.redhat.com/errata/RHSA-2023:6813https://access.redhat.com/errata/RHSA-2023:7370https://access.redhat.com/errata/RHSA-2023:7379https://access.redhat.com/errata/RHSA-2023:7382https://access.redhat.com/errata/RHSA-2023:7389https://access.redhat.com/errata/RHSA-2023:7411https://access.redhat.com/errata/RHSA-2023:7418https://access.redhat.com/errata/RHSA-2023:7548https://access.redhat.com/errata/RHSA-2023:7549https://access.redhat.com/errata/RHSA-2023:7554https://access.redhat.com/errata/RHSA-2024:0340https://access.redhat.com/errata/RHSA-2024:0378https://access.redhat.com/errata/RHSA-2024:0412https://access.redhat.com/errata/RHSA-2024:0461https://access.redhat.com/errata/RHSA-2024:0554https://access.redhat.com/errata/RHSA-2024:0562https://access.redhat.com/errata/RHSA-2024:0563https://access.redhat.com/errata/RHSA-2024:0575https://access.redhat.com/errata/RHSA-2024:0593https://access.redhat.com/errata/RHSA-2024:1961https://access.redhat.com/errata/RHSA-2024:2006https://access.redhat.com/errata/RHSA-2024:2008https://access.redhat.com/security/cve/CVE-2023-3812https://bugzilla.redhat.com/show_bug.cgi?id=2224048https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=363a5328f4b0
2023-07-24
Published