CVE-2023-23454

CVSS v3.1 5.5 (Medium)
55% Progress
EPSS 0.04 % (15th)
0.04% Progress
Affected Products 2
Advisories 76

cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).

Weaknesses
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2023-01-12 07:15:08
(20 months ago)
Updated Date
2023-05-03 14:15:31
(16 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.6.12 version and 6.1.4 and prior versions cpe:2.3:o:linux:linux_kernel >= 2.6.12 <= 6.1.4

Configuration #2

    CPE23 From Up To
  Debian Linux 11.0 cpe:2.3:o:debian:debian_linux:11.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...