First published: Wed Apr 19 2023(Updated: )
A vulnerability was found in compare_netdev_and_ip in drivers/infiniband/core/cma.c in RDMA in the Linux Kernel. The improper cleanup results in out-of-boundary read, where a local user can utilize this problem to crash the system or escalation of privilege.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Governance, Identity Manager software component | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager virtual appliance component | <=ISVG 10.0.2 | |
Linux Kernel | >=6.0<6.1.81 | |
Linux Kernel | >=6.2<6.3 | |
Linux Kernel | >=6.0<6.3 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.10-1 6.12.11-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2176 has a high severity rating due to its potential for system crashes and privilege escalation.
To mitigate CVE-2023-2176, users should upgrade to the latest patched versions of the Linux Kernel and any affected IBM Security Verify Governance components.
CVE-2023-2176 affects the Linux Kernel versions from 6.0 to 6.3 and IBM Security Verify Governance, Identity Manager components up to version ISVG 10.0.2.
CVE-2023-2176 is primarily applicable to local users, as it requires local access to exploit the vulnerability.
Exploiting CVE-2023-2176 can lead to system crashes and unauthorized escalation of privileges on the affected systems.