CVE-2023-1076: Medium severity Linux Linux kernel vulnerability

Published Feb 26, 2023
·
Updated

A flaw found in the Linux Kernel. The tun/tap sockets have their socket UID hardcoded to 0 due to a type confusion in their initialization function. While it will be often correct, as tuntap devices require CAPNETADMIN, it may not always be the case, e.g., a non-root user only having that capability. This would make tun/tap sockets being incorrectly treated in filtering/routing decisions, possibly bypassing network filters.

References: https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=66b2c338adce580dfce2199591e65e2bab889cff https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=a096ccca6e503a5c575717ff8a36ace27510ab0a

Other sources

A flaw was found in the Linux Kernel. The tun/tap sockets have their socket UID hardcoded to 0 due to a type confusion in their initialization function. While it will be often correct, as tuntap devices require CAPNETADMIN, it may not always be the case, e.g., a non-root user only having that capability. This would make tun/tap sockets being incorrectly treated in filtering/routing decisions, possibly bypassing network filters.

Launchpad

Affected Software

3 affected componentsFixes available
redhat/kernel<6.1.16
6.1.16
Linux Linux kernel
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Feb 26, 2023
Data Sourced
via Red Hat·05:20 PM
DescriptionSeverityAffected Software
Mar 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:13 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·05:20 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-1076?

CVE-2023-1076 has a high severity rating due to a vulnerability in the Linux Kernel affecting tun/tap sockets.

2

How do I fix CVE-2023-1076?

To fix CVE-2023-1076, upgrade to kernel version 6.1.16 or apply the relevant patches available for affected distributions.

3

Which versions of Linux Kernel are affected by CVE-2023-1076?

CVE-2023-1076 affects multiple versions including pre-6.1.16 and specific versions in the 5.10 and 6.x series without the patch.

4

Under what conditions does CVE-2023-1076 pose a risk?

CVE-2023-1076 poses a risk particularly when non-root users gain unintended access through tun/tap socket misuse.

5

What is the root cause of CVE-2023-1076?

The root cause of CVE-2023-1076 is a type confusion in the initialization function for tun/tap sockets leading to hard-coded UID issues.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203