UBUNTU-CVE-2023-3090
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-3090
UBUNTU-CVE-2023-3090
Summary:
Details: A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation. The out-of-bounds write is caused by missing skb->cb initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled. We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.
References: https://ubuntu.com/security/CVE-2023-3090, https://git.kernel.org/linus/90cbed5247439a966b645b34eb0a2e037836ea8e, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=90cbed5247439a966b645b34eb0a2e037836ea8e, https://kernel.dance/90cbed5247439a966b645b34eb0a2e037836ea8e, https://ubuntu.com/security/notices/USN-6231-1, https://ubuntu.com/security/notices/USN-6246-1, https://ubuntu.com/security/notices/USN-6250-1, https://ubuntu.com/security/notices/USN-6251-1, https://ubuntu.com/security/notices/USN-6252-1, https://ubuntu.com/security/notices/USN-6254-1, https://ubuntu.com/security/notices/USN-6255-1, https://ubuntu.com/security/notices/USN-6260-1, https://ubuntu.com/security/notices/USN-6261-1, https://ubuntu.com/security/notices/USN-6385-1, https://www.cve.org/CVERecord?id=CVE-2023-3090
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
