CVE-2023-52735
published 2024-05-21CVE-2023-52735: In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto…
PriorityP345critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
1.22%
65.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
sock_map proto callbacks should never call themselves by design. Protect
against bugs like [1] and break out of the recursive loop to avoid a stack
overflow in favor of a resource leak.
[1] https://lore.kernel.org/all/[email protected]/
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.15-1 (bookworm) | linux 6.1.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 5.14.19 < 5.15 | 5.15 |
| linux | linux | >= 5.15.3 < 5.15.95 | 5.15.95 |
| linux | linux | >= c5cc0d23c5414d23438c5024890e367cc5a0e645 < f312367f5246e04df564d341044286e9e37a97ba | f312367f5246e04df564d341044286e9e37a97ba |
| linux | linux | >= c5d2177a72a1659554922728fc407f59950aa929 < 7499859881488da97589f3c79cc66fa75748ad49 | 7499859881488da97589f3c79cc66fa75748ad49 |
| linux | linux | >= c5d2177a72a1659554922728fc407f59950aa929 < 5b4a79ba65a1ab479903fff2e604865d229b70a9 | 5b4a79ba65a1ab479903fff2e604865d229b70a9 |
| linux | linux_kernel | < 5.15.95 | 5.15.95 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 5.16 < 6.1.13 | 6.1.13 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-47rw-4rpj-m5g9: In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
sock_map pro
ghsa_unreviewed·2024-05-21
CVE-2023-52735 [CRITICAL] CWE-120 GHSA-47rw-4rpj-m5g9: In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
sock_map pro
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
sock_map proto callbacks should never call themselves by design. Protect
against bugs like [1] and break out of the recursive loop to avoid a stack
overflow in favor of a resource leak.
[1] https://lore.kernel.org/all/[email protected]/
OSV
CVE-2023-52735: In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto
osv·2024-05-21·CVSS 9.1
CVE-2023-52735 [CRITICAL] CVE-2023-52735: In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto callbacks should never call themselves by design. Protect against bugs like [1] and break out of the recursive loop to avoid a stack overflow in favor of a resource leak. [1] https://lore.kernel.org/all/[email protected]/
Red Hat
kernel: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
vendor_redhat·2024-05-21·CVSS 9.1
CVE-2023-52735 [CRITICAL] CWE-121 kernel: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
kernel: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
sock_map proto callbacks should never call themselves by design. Protect
against bugs like [1] and break out of the recursive loop to avoid a stack
overflow in favor of a resource leak.
[1] https://lore.kernel.org/all/[email protected]/
Statement: Redhat has rated this vulnerability as Low severity as by default in RHEL system the BPF sockmap feature is disabled by default which is needed for this vulnerability to be exploitable, on top of that local access and higher privileges are required to exploit this vulnerability and a successful exploitation will on
Debian
CVE-2023-52735: linux - In the Linux kernel, the following vulnerability has been resolved: bpf, sockma...
vendor_debian·2023·CVSS 9.1
CVE-2023-52735 [CRITICAL] CVE-2023-52735: linux - In the Linux kernel, the following vulnerability has been resolved: bpf, sockma...
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto callbacks should never call themselves by design. Protect against bugs like [1] and break out of the recursive loop to avoid a stack overflow in favor of a resource leak. [1] https://lore.kernel.org/all/[email protected]/
Scope: local
bookworm: resolved (fixed in 6.1.15-1)
bullseye: resolved
forky: resolved (fixed in 6.1.15-1)
sid: resolved (fixed in 6.1.15-1)
trixie: resolved (fixed in 6.1.15-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/5b4a79ba65a1ab479903fff2e604865d229b70a9https://git.kernel.org/stable/c/7499859881488da97589f3c79cc66fa75748ad49https://git.kernel.org/stable/c/f312367f5246e04df564d341044286e9e37a97bahttps://git.kernel.org/stable/c/5b4a79ba65a1ab479903fff2e604865d229b70a9https://git.kernel.org/stable/c/7499859881488da97589f3c79cc66fa75748ad49https://git.kernel.org/stable/c/f312367f5246e04df564d341044286e9e37a97ba
2024-05-21
Published