CVE-2023-45871Incorrect Calculation of Buffer Size in Kernel

Severity
7.5HIGHNVD
OSV9.8OSV5.5
EPSS
0.0%
top 93.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 15
Latest updateOct 5

Description

An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages5 packages

NVDlinux/linux_kernel3.44.14.326+7
Debianlinux/linux_kernel< 5.10.197-1+3
Ubuntulinux/linux_kernel< 5.4.0-167.184+3
debiandebian/linux< linux 6.1.55-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

14
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2023-12-05
OSV
linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gkeop vulnerabilities2023-11-30
OSV
linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15 vulnerabilities2023-11-30
OSV
linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15 vulnerabilities2023-11-30
OSV
linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-gcp, linux-gcp-6.2 vulnerabilities2023-11-30

📋Vendor Advisories

16
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.12023-12-14
Ubuntu
Linux kernel vulnerabilities2023-12-05
Ubuntu
Linux kernel vulnerabilities2023-11-30
Ubuntu
Linux kernel vulnerabilities2023-11-30
Ubuntu
Linux kernel vulnerabilities2023-11-30

📄Research Papers

2
arXiv
Real-VulLLM: An LLM Based Assessment Framework in the Wild2025-10-05
arXiv
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond2025-06-11

💬Community

1
Bugzilla
CVE-2023-45871 kernel: IGB driver inadequate buffer size for frames larger than MTU2023-10-17
CVE-2023-45871 — Incorrect Calculation of Buffer Size | cvebase