CVE-2023-42752Integer Overflow or Wraparound in Linux

Severity
5.5MEDIUMNVD
OSV7.8OSV7.0OSV6.5OSV5.7
EPSS
0.0%
top 97.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateNov 28

Description

An integer overflow flaw was found in the Linux kernel. This issue leads to the kernel allocating `skb_shared_info` in the userspace, which is exploitable in systems without SMAP protection since `skb_shared_info` contains references to function pointers.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Debianlinux/linux_kernel< 6.1.55-1+2
Ubuntulinux/linux_kernel< 5.4.0-165.182+6
debiandebian/linux< linux 6.1.55-1 (bookworm)

Patches

🔴Vulnerability Details

22
OSV
Kernel Live Patch Security Notice2023-11-28
OSV
linux-nvidia-6.2 vulnerabilities2023-10-31
OSV
linux vulnerabilities2023-10-30
OSV
linux-iot, linux-raspi, linux-raspi-5.4 vulnerabilities2023-10-30
OSV
linux-oracle-5.15 vulnerabilities2023-10-26

📋Vendor Advisories

20
Ubuntu
Kernel Live Patch Security Notice2023-11-28
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2023-10-31
Ubuntu
Linux kernel vulnerabilities2023-10-30
Ubuntu
Linux kernel vulnerabilities2023-10-30
Ubuntu
Linux kernel (Oracle) vulnerabilities2023-10-26

💬Community

1
Bugzilla
CVE-2023-42752 kernel: integer overflow in igmpv3_newpack leading to exploitable memory access2023-09-20