CVE-2023-1390: High severity Linux Linux kernel vulnerability
A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipclinkxmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packets to a system with a UDP bearer results in the CPU utilization for the system to instantly spike to 100%, causing a denial of service condition.
Other sources
A remote DoS vulnerability was found in the the Linux TIPC kernel module. Sending 2 small UDP packets to a system with a UDP bearer results in the CPU utilization for the system to instantly spike to 100% and the system is unresponsive to input. The while loop in tipclinkxmit() hits an unknown state while attempting to parse SKB's which are not in the queue, resulting in DoS.
Upstream fix: https://github.com/torvalds/linux/commit/b77413446408fdd256599daf00d5be72b5f3e7c6
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.rt7.72.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.el8 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.83.1.el8_1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.109.1.el8_2 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.109.1.rt13.160.el8_2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.11
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2023-1390?
The severity of CVE-2023-1390 is classified as high due to the potential for remote denial of service.
How do I fix CVE-2023-1390?
To fix CVE-2023-1390, update your kernel to the specified versions that contain the security patch.
Which versions of the Linux kernel are affected by CVE-2023-1390?
CVE-2023-1390 affects several versions of the Linux kernel, specifically those prior to 4.18.0-305.el8.
What are the symptoms of exploitation of CVE-2023-1390?
Exploitation of CVE-2023-1390 may lead to increased CPU utilization, causing system performance degradation.
Is there a workaround for CVE-2023-1390 if I cannot immediately update my kernel?
A potential workaround for CVE-2023-1390 is to limit UDP traffic to the affected system until an update can be applied.