« List of all CVEs

CVE-2023-2860

Out-of-bounds read when setting hmac data

Published: 7/24/2023 Last updated: 3/5/2025 Reserved: 5/24/2023

An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 4.4 Medium CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Opam packages affected (29)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes ortools_solvers orun rawlink rawlink-eio rawlink-lwt restricted shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (15)

Product Vendor Version
Fedora Fedora <= < 9.6
Red Hat Enterprise Linux 7 Red Hat <= 5.4.*
Fedora Fedora <= 4.19.*
Red Hat Enterprise Linux 6 Red Hat <= <= 1.7.2
Red Hat Enterprise Linux 7 Red Hat <= <= 3.5.1
Red Hat Enterprise Linux 8 Red Hat <= <= 1.2.10
Red Hat Enterprise Linux 9 Red Hat <= <= 3.3.5
Red Hat Enterprise Linux 6 Red Hat < ba08cbc5b53e151d0acf1930fb526fc65b7f3e65
Red Hat Enterprise Linux 8 Red Hat < be4df018c0be5ebecf1ca510feacc23be415cefc
Red Hat Enterprise Linux 7 Red Hat <= *
Red Hat Enterprise Linux 8 Red Hat <= <= 4.4.7
Red Hat Enterprise Linux 8 Red Hat <= 5.10.*
Red Hat Enterprise Linux 7 Red Hat <= 5.2.0.12
Red Hat Enterprise Linux 9 Red Hat <= <= 1.2
kernel n/a 5.15

References (12)