CVE-2023-0881: DDoS in Ubuntu package linux-bluefield
Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nftlookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0881?
CVE-2023-0881 has a high severity level due to its potential to cause a kernel crash when subjected to a DDoS attack on TCP port 22.
How do I fix CVE-2023-0881?
To fix CVE-2023-0881, update to the latest version of the linux-bluefield package that includes the necessary patches.
What systems are affected by CVE-2023-0881?
CVE-2023-0881 affects the Ubuntu linux-bluefield systems.
What are the consequences of exploiting CVE-2023-0881?
Exploiting CVE-2023-0881 can lead to a kernel crash, resulting in a denial-of-service condition.
When was CVE-2023-0881 reported?
CVE-2023-0881 was reported as part of a bug linked to the backport of a commit for the nft_lookup functionality.