UBUNTU-CVE-2023-31436
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-31436
UBUNTU-CVE-2023-31436
Summary:
Details: qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.
References: https://ubuntu.com/security/CVE-2023-31436, https://git.kernel.org/linus/3037933448f60f9acb705997eae62013ecb81e0d, https://github.com/torvalds/linux/commit/3037933448f60f9acb705997eae62013ecb81e0d, https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.13, https://www.spinics.net/lists/stable-commits/msg294885.html, https://ubuntu.com/security/notices/USN-6127-1, https://ubuntu.com/security/notices/USN-6130-1, https://ubuntu.com/security/notices/USN-6131-1, https://ubuntu.com/security/notices/USN-6132-1, https://ubuntu.com/security/notices/USN-6135-1, https://ubuntu.com/security/notices/USN-6149-1, https://ubuntu.com/security/notices/USN-6150-1, https://ubuntu.com/security/notices/USN-6162-1, https://ubuntu.com/security/notices/USN-6173-1, https://ubuntu.com/security/notices/USN-6175-1, https://ubuntu.com/security/notices/USN-6186-1, https://ubuntu.com/security/notices/USN-6222-1, https://ubuntu.com/security/notices/USN-6256-1, https://ubuntu.com/security/notices/USN-6385-1, https://ubuntu.com/security/notices/USN-6460-1, https://www.cve.org/CVERecord?id=CVE-2023-31436
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
