CVE-2023-3107: Remote denial of service in IPv6 fragment reassembly
A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3107?
CVE-2023-3107 is a vulnerability that allows an attacker to trigger a kernel panic, resulting in a denial of service, by sending carefully crafted IPv6 packets that trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field.
How severe is CVE-2023-3107?
CVE-2023-3107 has a severity rating of 7.5, which is considered high.
Which software versions are affected by CVE-2023-3107?
FreeBSD versions 12.4, 12.4-p1, 12.4-p2, 12.4-p3, 12.4-rc2-p1, 12.4-rc2-p2, 13.1, 13.1-b1-p1, 13.1-b2-p2, 13.1-p1, 13.1-p2, 13.1-p3, 13.1-p4, 13.1-p5, 13.1-p6, 13.1-p7, 13.1-p8, 13.1-rc1-p1, 13.2, and 13.2-p1 are affected by CVE-2023-3107.
How can I fix the CVE-2023-3107 vulnerability?
To fix the CVE-2023-3107 vulnerability, it is recommended to update to the latest available version of FreeBSD or apply the necessary patches provided by the vendor.
Where can I find more information about CVE-2023-3107?
You can find more information about CVE-2023-3107 on the FreeBSD Security Advisories website (https://security.FreeBSD.org/advisories/FreeBSD-SA-23:06.ipv6.asc) and the NetApp Security Advisory website (https://security.netapp.com/advisory/ntap-20230804-0001/).