« List of all CVEs

CVE-2023-2860

Out-of-bounds read when setting hmac data

Published: 7/24/2023 Last updated: 3/5/2025 Reserved: 5/24/2023

An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated buffer. This flaw allows a privileged local user to disclose sensitive information on affected installations of the Linux kernel.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 4.4 Medium CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Opam packages affected (27)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes orun rawlink rawlink-eio rawlink-lwt shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (9)

Product Vendor Version
Fedora Fedora < publication
Red Hat Enterprise Linux 6 Red Hat 8.2.0
Red Hat Enterprise Linux 7 Red Hat 7.0.0
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat 7.0.5
Red Hat Enterprise Linux 8 Red Hat 7.0.4
Red Hat Enterprise Linux 7 Red Hat <= 2.4.1
Red Hat Enterprise Linux 9 Red Hat < 1.0.6
kernel n/a n/a

References (6)