CVE-2023-2019: Linux Kernel netdevsim Improper Update of Reference Count Denial-of-Service Vulnerability
A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on the system.
Other sources
A reference count issue was found in the Linux kernel's netdevsim device driver. Quoting ZDI security advisory [1]:
"This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the scheduling of events. The issue results from the improper management of a reference count. An attacker can leverage this vulnerability to create a denial-of-service condition on the system."
[1] https://www.zerodayinitiative.com/advisories/ZDI-CAN-17811/
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2019?
CVE-2023-2019 has a high severity level due to its potential to create a denial of service condition.
How do I fix CVE-2023-2019?
To fix CVE-2023-2019, update the affected Linux kernel to version 6.0 or later.
Which systems are affected by CVE-2023-2019?
CVE-2023-2019 affects Linux kernel versions up to, but not including, 6.0 and Red Hat Enterprise Linux version 9.0.
What impact does CVE-2023-2019 have?
The impact of CVE-2023-2019 allows an attacker to create a denial of service condition which can disrupt system operations.
Is there a known exploit for CVE-2023-2019?
As of now, there are no publicly known exploits specifically targeting CVE-2023-2019.