cbcvebase.
CVE-2023-4459
published 2023-08-21

CVE-2023-4459: A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel. This issue may allow a local attacker with normal user privilege to cause a denial of service due to a missing sanity check during cleanup.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.11-1 (bookworm)linux 5.17.11-1 (bookworm)
linuxlinux_kernel< 5.185.18
linuxlinux_kernel>= 0 < 5.10.120-15.10.120-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 4.4.0-245.2794.4.0-245.279
msrccbl2_kernel_5.15.126.1-1_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM