CLSA-2023-1683229770

    Dashboard / Vulnerabilities / CLSA-2023-1683229770

    CLSA-2023-1683229770

    Published: 4 May 2023Last Modified: 1 Jun 2026

    Summary: kernel: Fix of 22 CVEs

    Details: - media: rc: Fix use-after-free bugs caused by ene_tx_irqsim() {CVE-2023-1118} - net: mpls: fix stale pointer if allocation fails during device rename {CVE-2023-26545} - net/ulp: prevent ULP without clone op from entering the LISTEN status {CVE-2023-0461} - Bluetooth: L2CAP: Fix u8 overflow {CVE-2022-45934} - nfp: fix use-after-free in area_cache_get() {CVE-2022-3545} - Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del() {CVE-2022-3640} - mISDN: fix use-after-free bugs in l1oip timer handlers {CVE-2022-3565} - usb: mon: make mmapped memory read only {CVE-2022-43750} - ath9k: fix use-after-free in ath9k_hif_usb_rx_cb {CVE-2022-1679} - netfilter: nf_queue: do not allow packet truncation below transport header offset {CVE-2022-36946} - netfilter: nf_tables: disallow non-stateful expression in sets earlier {CVE-2022-32250} - perf: Fix sys_perf_event_open() race against self {CVE-2022-1729} - openvswitch: fix OOB access in reserve_sfa_size() {CVE-2022-2639} - can: usb_8dev: usb_8dev_start_xmit(): fix double dev_kfree_skb() in error path {CVE-2022-28388} - drivers: net: slip: fix NPD bug in sl_tx_timeout() {CVE-2022-41858} - media: em28xx: initialize refcount before kref_get {CVE-2022-3239} - can: ems_usb: ems_usb_start_xmit(): fix double dev_kfree_skb() in error path {CVE-2022-28390} - ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE {CVE-2022-30594} - af_key: add __GFP_ZERO flag for compose_sadb_supported in function pfkey_register {CVE-2022-1353} - Bluetooth: sco: Fix lock_sock() blockage by memcpy_from_msg() {CVE-2021-3640} - igmp: Add ip_mc_list lock in ip_check_mc_rcu {CVE-2022-20141} - af_unix: fix garbage collect vs MSG_PEEK {CVE-2021-0920}

    Affected packages

    Package

    Name: bpftool

    Purl: pkg:rpm/tuxcare/bpftool?distro=centos-8.4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.18.0-305.25.1.el8_4.tuxcare.els7

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2023-1683229770 | CVE-DB