« List of all CVEs

CVE-2023-3812

Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags

Published: 7/24/2023 Last updated: 3/5/2025 Reserved: 7/20/2023

An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.8 High CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (27)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes orun rawlink rawlink-eio rawlink-lwt shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (33)

Product Vendor Version
Red Hat Enterprise Linux 9 Red Hat < 6.0.6003.21218
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat 24.0 ap383346
Red Hat Enterprise Linux 9 Red Hat 24.0 ap382487
Red Hat Enterprise Linux 6 Red Hat 24.0 ap383247
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions Red Hat <= 2.9.2
Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat 24.0 ap382945
Red Hat Enterprise Linux 8 Red Hat <= 5.4.*
Red Hat Enterprise Linux 8.2 Telecommunications Update Service Red Hat 24.0 ap383390
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat 24.0 ap381285
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat 10 Version 1803 for 32-bit Systems
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat 12.2.4
Red Hat Enterprise Linux 7 Red Hat < 3.0.0.6.102_22188
Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Version 1.6.9.0 and earlier
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat 24.0 ap382952
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat Android-13
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat 24.0 ap382976
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat Android-11
Red Hat Enterprise Linux 9 Red Hat Linux SDK versions less than TLM7.3.275.0-82
Red Hat Enterprise Linux 8.2 Telecommunications Update Service Red Hat 10 for 32-bit Systems
Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat 12.2.6
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat 24.0 ap381031
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat 24.0 ap383297
Red Hat Enterprise Linux 7 Red Hat 24.0 ap381515
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat 7.3.2.2
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat 14.1.1.0.0
Red Hat Enterprise Linux 8 Red Hat 12.1.1-12.1.3
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat 10 Version 1709 for x64-based Systems
Red Hat Enterprise Linux 9 Red Hat 24.0 ap383754
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat 378c157
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat 24.0 ap383178
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions Red Hat <= 5.18.*

References (52)