« List of all CVEs

CVE-2023-4194

Kernel: tap: tap_open(): correctly initialize socket uid next fix of i_uid to current_fsuid

Published: 8/7/2023 Last updated: 2/18/2026 Reserved: 8/6/2023

A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following upstream commits - a096ccca6e50 ("tun: tun_chr_open(): correctly initialize socket uid"), - 66b2c338adce ("tap: tap_open(): correctly initialize socket uid"), pass "inode->i_uid" to sock_init_data_uid() as the last parameter and that turns out to not be accurate.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.5 Medium CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Opam packages affected (29)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes ortools_solvers orun rawlink rawlink-eio rawlink-lwt restricted shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (14)

Product Vendor Version
Red Hat Enterprise Linux 9 Red Hat < 3d90607e7e6afa89768b0aaa915b58bd2b849276
Red Hat Enterprise Linux 7 Red Hat < 10.0.22631.2715
Red Hat Enterprise Linux 6 Red Hat < 1.5.0.123
Red Hat Enterprise Linux 7 Red Hat < 34d2cd3fccced12b958b8848e3eff0ee4296764c
Red Hat Enterprise Linux 9 Red Hat < 7208101ded1e9dcc52c8f0f8b16474211c871c1a
Red Hat Enterprise Linux 8 Red Hat < 4.15
Red Hat Enterprise Linux 6 Red Hat < c5fbf4f74c94fd60d5e9bf9f7f8268c3601562ca
Red Hat Enterprise Linux 9 Red Hat <= 5.4.*
Red Hat Enterprise Linux 7 Red Hat 4.15
Red Hat Enterprise Linux 8 Red Hat <= 4.19.*
Red Hat Enterprise Linux 7 Red Hat < 2.0.0
Red Hat Enterprise Linux 9 Red Hat < 10.0.25398.531
Red Hat Virtualization 4 Red Hat <= 5.10.*
Red Hat Virtualization 4 Red Hat < 2.0.0.409

References (36)

Credits (2)