Severity
8.8HIGHNVD
OSV9.8OSV7.0OSV5.7OSV4.7
EPSS
15.9%
top 5.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29
Latest updateFeb 12

Description

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel5.115.15.121+2
Debianlinux/linux_kernel< 6.1.52-1+2
Ubuntulinux/linux_kernel< 5.15.0-86.96
debiandebian/linux< linux 6.1.52-1 (bookworm)

Patches

🔴Vulnerability Details

10
OSV
linux-starfive-6.2 vulnerabilities2023-11-28
OSV
linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-gcp, linux-gcp-6.2, linux-hwe-6.2, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-6.2, linux-oracle, linux-2023-10-31
OSV
linux-nvidia-6.2 vulnerabilities2023-10-31
OSV
linux-intel-iotg-5.15 vulnerabilities2023-10-24
OSV
linux-raspi vulnerabilities2023-10-19

📋Vendor Advisories

11
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS2025-02-12
Ubuntu
Linux kernel (StarFive) vulnerabilities2023-11-28
Ubuntu
Linux kernel vulnerabilities2023-10-31
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2023-10-31
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2023-10-19

💬Community

1
Bugzilla
CVE-2023-44466 kernel: buffer overflow in ceph file net/ceph/messenger_v2.c2023-09-29
CVE-2023-44466 — Classic Buffer Overflow in Kernel | cvebase