← Back

CVE-2023-3090

nvd nist
Published: Jun 28, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.

Affected (10)

1 product
Linux Kernel
1 product
Debian Linux
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 3.19 to 4.14.316
From 4.15 to 4.19.284
From 4.20 to 5.4.244
From 5.11 to 5.15.113
From 5.16 to 6.1.30
From 5.5 to 5.10.181
From 6.2 to 6.3.4
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Version 12.0

References (18)

Source: cve-coordination@google.com
Third Party AdvisoryVDB Entry
Source: cve-coordination@google.com
Third Party AdvisoryVDB Entry
Source: cve-coordination@google.com
Mailing List
Source: cve-coordination@google.com
Mailing ListThird Party Advisory
Source: cve-coordination@google.com
Third Party Advisory
Source: cve-coordination@google.com
Third Party Advisory
Source: cve-coordination@google.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.