CVE-2023-52577
published 2024-03-02CVE-2023-52577: In the Linux kernel, the following vulnerability has been resolved: dccp: fix dccp_v4_err()/dccp_v6_err() again dh->dccph_x is the 9th byte (offset 8) in…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
dccp: fix dccp_v4_err()/dccp_v6_err() again
dh->dccph_x is the 9th byte (offset 8) in "struct dccp_hdr",
not in the "byte 7" as Jann claimed.
We need to make sure the ICMP messages are big enough,
using more standard ways (no more assumptions).
syzbot reported:
BUG: KMSAN: uninit-value in pskb_may_pull_reason include/linux/skbuff.h:2667 [inline]
BUG: KMSAN: uninit-value in pskb_may_pull include/linux/skbuff.h:2681 [inline]
BUG: KMSAN: uninit-value in dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94
pskb_may_pull_reason include/linux/skbuff.h:2667 [inline]
pskb_may_pull include/linux/skbuff.h:2681 [inline]
dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94
icmpv6_notify+0x4c7/0x880 net/ipv6/icmp.c:867
icmpv6_rcv+0x19d5/0x30d0
ip6_protocol_deliver_rcu+0xda6/0x2a60 net/ipv6/ip6_input.c:438
ip6_input_finish net/ipv6/ip6_input.c:483 [inline]
NF_HOOK include/linux/netfilter.h:304 [inline]
ip6_input+0x15d/0x430 net/ipv6/ip6_input.c:492
ip6_mc_input+0xa7e/0xc80 net/ipv6/ip6_input.c:586
dst_input include/net/dst.h:468 [inline]
ip6_rcv_finish+0x5db/0x870 net/ipv6/ip6_input.c:79
NF_HOOK include/linux/netfilter.h:304 [inline]
ipv6_rcv+0xda/0x390 net/ipv6/ip6_input.c:310
__netif_receive_skb_one_core net/core/dev.c:5523 [inline]
__netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5637
netif_receive_skb_internal net/core/dev.c:5723 [inline]
netif_receive_skb+0x58/0x660 net/core/dev.c:5782
tun_rx_batched+0x83b/0x920
tun_get_user+0x564c/0x6940 drivers/net/tun.c:2002
tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048
call_write_iter include/linux/fs.h:1985 [inline]
new_sync_write fs/read_write.c:491 [inline]
vfs_write+0x8ef/0x15c0 fs/read_write.c:584
ksys_write+0x20f/0x4c0 fs/read_write.c:637
__do_sys_write fs/read_write.c:649 [inline]
__se_sys_write fs/read_write.c:646 [inline]
__x64_sys_write+0x93/0xd0 fs/read_write.c:646
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x41/0xc0 arch/x86/entry/common.c:80
en
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 177212bf6dc1ff2d13d0409cddc5c9e81feec63d < 62c218124fe58372e0e1f60d5b634d21c264b337 | 62c218124fe58372e0e1f60d5b634d21c264b337 |
| linux | linux | >= 3533e10272555c422a7d51ebc0ce8c483429f7f2 < 4600beae416d754a3cedbb1ecea8181ec05073b6 | 4600beae416d754a3cedbb1ecea8181ec05073b6 |
| linux | linux | >= 4.14.326 < 4.14.327 | 4.14.327 |
| linux | linux | >= 4.19.295 < 4.19.296 | 4.19.296 |
| linux | linux | >= 4b8a938e329ae4eb54b73b0c87b5170607b038a8 < 60d73c62e3e4464f375758b6f2459c13d46465b6 | 60d73c62e3e4464f375758b6f2459c13d46465b6 |
| linux | linux | >= 5.10.195 < 5.10.198 | 5.10.198 |
| linux | linux | >= 5.15.132 < 5.15.134 | 5.15.134 |
| linux | linux | >= 5.4.257 < 5.4.258 | 5.4.258 |
| linux | linux | >= 6.1.53 < 6.1.56 | 6.1.56 |
| linux | linux | >= 6.4.16 < 6.5 | 6.5 |
| linux | linux | >= 6.5.3 < 6.5.6 | 6.5.6 |
| linux | linux | >= 6ecf09699eb1554299aa1e7fd13e9e80f656c2f9 < 26df9ab5de308caa1503d937533c56c35793018d | 26df9ab5de308caa1503d937533c56c35793018d |
| linux | linux | >= 7a7dd70cb954d3efa706a429687ded88c02496fa < a6f4d582e25d512c9b492670b6608436694357b3 | a6f4d582e25d512c9b492670b6608436694357b3 |
| linux | linux | >= 977ad86c2a1bcaf58f01ab98df5cc145083c489c < 6af289746a636f71f4c0535a9801774118486c7a | 6af289746a636f71f4c0535a9801774118486c7a |
| linux | linux | >= ec620c34f5fa5d055f9f6136a387755db6157712 < 1512d8f45d3c5d0b5baa00bd8e600492fa569f40 | 1512d8f45d3c5d0b5baa00bd8e600492fa569f40 |
| linux | linux | >= f8a7f10a1dccf9868ff09342a73dce27501b86df < 73be49248a04746096339a48a33fa2f03bd85969 | 73be49248a04746096339a48a33fa2f03bd85969 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: dccp: out-of-bounds access in dccp_v4_err() and dccp_v6_err()
vendor_redhat·2024-03-02·CVSS 5.5
CVE-2023-52577 [MEDIUM] CWE-787 kernel: dccp: out-of-bounds access in dccp_v4_err() and dccp_v6_err()
kernel: dccp: out-of-bounds access in dccp_v4_err() and dccp_v6_err()
In the Linux kernel, the following vulnerability has been resolved:
dccp: fix dccp_v4_err()/dccp_v6_err() again
dh->dccph_x is the 9th byte (offset 8) in "struct dccp_hdr",
not in the "byte 7" as Jann claimed.
We need to make sure the ICMP messages are big enough,
using more standard ways (no more assumptions).
syzbot reported:
BUG: KMSAN: uninit-value in pskb_may_pull_reason include/linux/skbuff.h:2667 [inline]
BUG: KMSAN: uninit-value in pskb_may_pull include/linux/skbuff.h:2681 [inline]
BUG: KMSAN: uninit-value in dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94
pskb_may_pull_reason include/linux/skbuff.h:2667 [inline]
pskb_may_pull include/linux/skbuff.h:2681 [inline]
dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94
icmpv6_no
Debian
CVE-2023-52577: linux - In the Linux kernel, the following vulnerability has been resolved: dccp: fix d...
vendor_debian·2023·CVSS 5.5
CVE-2023-52577 [MEDIUM] CVE-2023-52577: linux - In the Linux kernel, the following vulnerability has been resolved: dccp: fix d...
In the Linux kernel, the following vulnerability has been resolved: dccp: fix dccp_v4_err()/dccp_v6_err() again dh->dccph_x is the 9th byte (offset 8) in "struct dccp_hdr", not in the "byte 7" as Jann claimed. We need to make sure the ICMP messages are big enough, using more standard ways (no more assumptions). syzbot reported: BUG: KMSAN: uninit-value in pskb_may_pull_reason include/linux/skbuff.h:2667 [inline] BUG: KMSAN: uninit-value in pskb_may_pull include/linux/skbuff.h:2681 [inline] BUG: KMSAN: uninit-value in dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94 pskb_may_pull_reason include/linux/skbuff.h:2667 [inline] pskb_may_pull include/linux/skbuff.h:2681 [inline] dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94 icmpv6_notify+0x4c7/0x880 net/ipv6/icmp.c:867 icmpv6_rcv+0x19d5/0x30d0 ip6_proto
GHSA
GHSA-85v9-53x3-q4xp: In the Linux kernel, the following vulnerability has been resolved:
dccp: fix dccp_v4_err()/dccp_v6_err() again
dh->dccph_x is the 9th byte (offset
ghsa_unreviewed·2024-03-03
CVE-2023-52577 [MEDIUM] CWE-908 GHSA-85v9-53x3-q4xp: In the Linux kernel, the following vulnerability has been resolved:
dccp: fix dccp_v4_err()/dccp_v6_err() again
dh->dccph_x is the 9th byte (offset
In the Linux kernel, the following vulnerability has been resolved:
dccp: fix dccp_v4_err()/dccp_v6_err() again
dh->dccph_x is the 9th byte (offset 8) in "struct dccp_hdr",
not in the "byte 7" as Jann claimed.
We need to make sure the ICMP messages are big enough,
using more standard ways (no more assumptions).
syzbot reported:
BUG: KMSAN: uninit-value in pskb_may_pull_reason include/linux/skbuff.h:2667 [inline]
BUG: KMSAN: uninit-value in pskb_may_pull include/linux/skbuff.h:2681 [inline]
BUG: KMSAN: uninit-value in dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94
pskb_may_pull_reason include/linux/skbuff.h:2667 [inline]
pskb_may_pull include/linux/skbuff.h:2681 [inline]
dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94
icmpv6_notify+0x4c7/0x880 net/ipv6/icmp.c:867
icmpv6_rcv+0x19d5/0x30d0
ip6_p
OSV
CVE-2023-52577: In the Linux kernel, the following vulnerability has been resolved: dccp: fix dccp_v4_err()/dccp_v6_err() again dh->dccph_x is the 9th byte (offset 8)
osv·2024-03-02·CVSS 5.5
CVE-2023-52577 [MEDIUM] CVE-2023-52577: In the Linux kernel, the following vulnerability has been resolved: dccp: fix dccp_v4_err()/dccp_v6_err() again dh->dccph_x is the 9th byte (offset 8)
In the Linux kernel, the following vulnerability has been resolved: dccp: fix dccp_v4_err()/dccp_v6_err() again dh->dccph_x is the 9th byte (offset 8) in "struct dccp_hdr", not in the "byte 7" as Jann claimed. We need to make sure the ICMP messages are big enough, using more standard ways (no more assumptions). syzbot reported: BUG: KMSAN: uninit-value in pskb_may_pull_reason include/linux/skbuff.h:2667 [inline] BUG: KMSAN: uninit-value in pskb_may_pull include/linux/skbuff.h:2681 [inline] BUG: KMSAN: uninit-value in dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94 pskb_may_pull_reason include/linux/skbuff.h:2667 [inline] pskb_may_pull include/linux/skbuff.h:2681 [inline] dccp_v6_err+0x426/0x1aa0 net/dccp/ipv6.c:94 icmpv6_notify+0x4c7/0x880 net/ipv6/icmp.c:867 icmpv6_rcv+0x19d5/0x30d0 ip6_proto
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1512d8f45d3c5d0b5baa00bd8e600492fa569f40https://git.kernel.org/stable/c/26df9ab5de308caa1503d937533c56c35793018dhttps://git.kernel.org/stable/c/4600beae416d754a3cedbb1ecea8181ec05073b6https://git.kernel.org/stable/c/60d73c62e3e4464f375758b6f2459c13d46465b6https://git.kernel.org/stable/c/62c218124fe58372e0e1f60d5b634d21c264b337https://git.kernel.org/stable/c/6af289746a636f71f4c0535a9801774118486c7ahttps://git.kernel.org/stable/c/73be49248a04746096339a48a33fa2f03bd85969https://git.kernel.org/stable/c/a6f4d582e25d512c9b492670b6608436694357b3https://git.kernel.org/stable/c/1512d8f45d3c5d0b5baa00bd8e600492fa569f40https://git.kernel.org/stable/c/26df9ab5de308caa1503d937533c56c35793018dhttps://git.kernel.org/stable/c/4600beae416d754a3cedbb1ecea8181ec05073b6https://git.kernel.org/stable/c/60d73c62e3e4464f375758b6f2459c13d46465b6https://git.kernel.org/stable/c/62c218124fe58372e0e1f60d5b634d21c264b337https://git.kernel.org/stable/c/6af289746a636f71f4c0535a9801774118486c7ahttps://git.kernel.org/stable/c/73be49248a04746096339a48a33fa2f03bd85969https://git.kernel.org/stable/c/a6f4d582e25d512c9b492670b6608436694357b3
2024-03-02
Published