CVE Vulnerabilities

CVE-2023-1390

Published: Mar 16, 2023 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packets to a system with a UDP bearer results in the CPU utilization for the system to instantly spike to 100%, causing a denial of service condition.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux 4.3 (including) 4.9.253 (excluding)
Linux_kernel Linux 4.10 (including) 4.14.217 (excluding)
Linux_kernel Linux 4.15 (including) 4.19.170 (excluding)
Linux_kernel Linux 4.20 (including) 5.4.92 (excluding)
Linux_kernel Linux 5.5 (including) 5.10.10 (excluding)
Linux_kernel Linux 5.11-rc1 (including) 5.11-rc1 (including)
Linux_kernel Linux 5.11-rc2 (including) 5.11-rc2 (including)
Linux_kernel Linux 5.11-rc3 (including) 5.11-rc3 (including)

References