A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs. This issue may allow a local user with CAP_NET_ADMIN privileges to crash the system.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Sep 2024 19:45:00 +0000
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2023-10-05T18:25:22.372Z
Updated: 2024-11-15T17:05:42.984Z
Reserved: 2023-09-13T11:03:47.962Z
Link: CVE-2023-42754
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-10-05T19:15:11.413
Modified: 2024-09-13T19:15:15.473
Link: CVE-2023-42754
Redhat