← Back

CVE-2023-46838

nvd nist
Published: Jan 29, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred data, these parts are directly translated into what Linux calls SKB fragments. Such converted request parts can, when for a particular SKB they are all of length zero, lead to a de-reference of NULL in core networking code.

Affected (10)

1 product
Linux Kernel
1 product
Fedora
1 product
Debian Linux
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 4.14 to 4.19.306
From 4.20 to 5.4.268
From 5.11 to 5.15.148
From 5.16 to 6.1.75
From 5.5 to 5.10.209
From 6.2 to 6.6.14
From 6.7 to 6.7.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 38
Version 39
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (11)

Source: security@xen.org
Mailing ListThird Party Advisory
Source: security@xen.org
Mailing ListThird Party Advisory
Source: security@xen.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.