CVE-2023-27567: High severity openbsd vulnerability
Published Mar 3, 2023
·Updated
In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
Affected Software
1 affected component
OpenBSD OpenBSD=7.2
Remediation
Event History
Mar 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-27567.
2
What is the affected software?
The affected software is OpenBSD 7.2.
3
What is the severity of CVE-2023-27567?
The severity of CVE-2023-27567 is high with a CVSS score of 7.5.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by sending a TCP packet with destination port 0 that matches a pf divert-to rule in OpenBSD 7.2.
5
Is there a patch available for CVE-2023-27567?
Yes, a patch is available for CVE-2023-27567. You can find the patch at the following links: [Link 1](https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/013_tcp.patch.sig), [Link 2](https://github.com/openbsd/src/commit/0a543725ccdd2a01669122ce79bb67e66ede77f2).