First published: Sat Feb 25 2023(Updated: )
A double free in net/mpls/af_mpls.c upon an allocation failure during the renaming of a device in Linux Kernel could allow a remote authenticated attacker from within the local network to cause an unknown impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <6.2 | 6.2 |
Linux Kernel | <6.1.13 | |
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp h410c firmware | ||
netapp h410c | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26545 is considered to have an impact that could lead to unknown consequences due to a double free vulnerability.
To mitigate CVE-2023-26545, update the Linux Kernel to version 6.1.13 or later, or apply specific patches if available.
CVE-2023-26545 affects versions of the Linux Kernel prior to 6.1.13.
Yes, CVE-2023-26545 allows remote authenticated attackers within the local network to exploit the vulnerability.
CVE-2023-26545 impacts systems running affected versions of the Linux Kernel, including certain configurations of IBM Security Verify Governance and NetApp firmware.