cbcvebase.
CVE-2023-52745
published 2024-05-21

CVE-2023-52745: In the Linux kernel, the following vulnerability has been resolved: IB/IPoIB: Fix legacy IPoIB due to wrong number of queues The cited commit creates child…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved: IB/IPoIB: Fix legacy IPoIB due to wrong number of queues The cited commit creates child PKEY interfaces over netlink will multiple tx and rx queues, but some devices doesn't support more than 1 tx and 1 rx queues. This causes to a crash when traffic is sent over the PKEY interface due to the parent having a single queue but the child having multiple queues. This patch fixes the number of queues to 1 for legacy IPoIB at the earliest possible point in time. BUG: kernel NULL pointer dereference, address: 000000000000036b PGD 0 P4D 0 Oops: 0000 [#1] SMP CPU: 4 PID: 209665 Comm: python3 Not tainted 6.1.0_for_upstream_min_debug_2022_12_12_17_02 #1 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 RIP: 0010:kmem_cache_alloc+0xcb/0x450 Code: ce 7e 49 8b 50 08 49 83 78 10 00 4d 8b 28 0f 84 cb 02 00 00 4d 85 ed 0f 84 c2 02 00 00 41 8b 44 24 28 48 8d 4a 01 49 8b 3c 24 8b 5c 05 00 4c 89 e8 65 48 0f c7 0f 0f 94 c0 84 c0 74 b8 41 8b RSP: 0018:ffff88822acbbab8 EFLAGS: 00010202 RAX: 0000000000000070 RBX: ffff8881c28e3e00 RCX: 00000000064f8dae RDX: 00000000064f8dad RSI: 0000000000000a20 RDI: 0000000000030d00 RBP: 0000000000000a20 R08: ffff8882f5d30d00 R09: ffff888104032f40 R10: ffff88810fade828 R11: 736f6d6570736575 R12: ffff88810081c000 R13: 00000000000002fb R14: ffffffff817fc865 R15: 0000000000000000 FS: 00007f9324ff9700(0000) GS:ffff8882f5d00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000000000036b CR3: 00000001125af004 CR4: 0000000000370ea0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: skb_clone+0x55/0xd0 ip6_finish_output2+0x3fe/0x690 ip6_finish_output+0xfa/0x310 ip6_send_skb+0x1e/0x60 udp_v6_send_skb+0x1e5/0x420 udpv6_sendmsg+0xb3c/0xe60 ? ip_mc_finish_output+0x180/0x180 ? __switch_to_asm+0x3a/0x60 ? _

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.12-1 (bookworm)linux 6.1.12-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.303 < 4.154.15
linuxlinux>= 4.19.270 < 4.204.20
linuxlinux>= 4.9.337 < 4.104.10
linuxlinux>= 5.10.163 < 5.10.1685.10.168
linuxlinux>= 5.15.86 < 5.15.945.15.94
linuxlinux>= 5.4.229 < 5.4.2325.4.232
linuxlinux>= 6.0.16 < 6.16.1
linuxlinux>= 6.1.2 < 6.1.126.1.12
linuxlinux>= ca48174a7643a7e6dd31c4338c5cde49552e138e < 1b4ef90cbcfa603b3bb536fbd6f261197012b6f61b4ef90cbcfa603b3bb536fbd6f261197012b6f6
linuxlinux>= d21714134505bc23daa0455b295f3b63730b3b42 < b1afb666c32931667c15ad1b58e7203f0119dcafb1afb666c32931667c15ad1b58e7203f0119dcaf
linuxlinux>= d4bf3fcccd188db9f3310d93472041cdefba97bf < 4a779187db39b2f32d048a752573e56e4e77807f4a779187db39b2f32d048a752573e56e4e77807f
linuxlinux>= dbc94a0fb81771a38733c0e8f2ea8c4fa6934dc1 < e632291a2dbce45a24cddeb5fe28fe71d724ba43e632291a2dbce45a24cddeb5fe28fe71d724ba43
linuxlinux>= ee0e9b2c4b9c35837553124b4912230a7e7c7212 < 7197460dcd43ff0e4a502ba855dd82d37c2848cc7197460dcd43ff0e4a502ba855dd82d37c2848cc
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.12-16.1.12-1
linuxlinux_kernel>= 0 < 6.1.12-16.1.12-1
linuxlinux_kernel>= 0 < 6.1.12-16.1.12-1
linuxlinux_kernel>= 4.14.303 < 4.154.15
linuxlinux_kernel>= 4.19.270 < 4.204.20
linuxlinux_kernel>= 4.9.337 < 4.104.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.