cbcvebase.
CVE-2023-52880
published 2024-05-24

CVE-2023-52880: In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc Any unprivileged user can…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.7th percentile
In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc Any unprivileged user can attach N_GSM0710 ldisc, but it requires CAP_NET_ADMIN to create a GSM network anyway. Require initial namespace CAP_NET_ADMIN to do that.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 7d303dee473ba3529d75b63491e9963342107bed7d303dee473ba3529d75b63491e9963342107bed
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 7a529c9023a197ab3bf09bb95df32a3813f7ba587a529c9023a197ab3bf09bb95df32a3813f7ba58
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < ada28eb4b9561aab93942f3224a2e41d76fe57faada28eb4b9561aab93942f3224a2e41d76fe57fa
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 2d154a54c58f9c8375bfbea9f7e51ba3bfb2e43a2d154a54c58f9c8375bfbea9f7e51ba3bfb2e43a
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 2b85977977cbd120591b23c2450e90a5806a71672b85977977cbd120591b23c2450e90a5806a7167
linuxlinux>= e1eaea46bb4020b38a141b84f88565d4603f8dd0 < 67c37756898a5a6b2941a13ae7260c89b54e0d8867c37756898a5a6b2941a13ae7260c89b54e0d88
linuxlinux_kernel< 4.19.3124.19.312
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 3.13.0-204.2553.13.0-204.255
linuxlinux_kernel>= 0 < 4.4.0-266.3004.4.0-266.300
linuxlinux_kernel>= 0 < 4.4.0-268.3024.4.0-268.302
linuxlinux_kernel>= 0 < 4.15.0-237.2494.15.0-237.249
linuxlinux_kernel>= 0 < 4.15.0-235.2474.15.0-235.247
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-57.596.8.0-57.59
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.