First published: Thu Jun 08 2023(Updated: )
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service. Upstream fix: <a href="https://github.com/torvalds/linux/commit/2b09d5d364986f724f17001ccfe4126b9b43a0be">https://github.com/torvalds/linux/commit/2b09d5d364986f724f17001ccfe4126b9b43a0be</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <6.2 | 6.2 |
IBM Security Verify Governance, Identity Manager software component | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager virtual appliance component | <=ISVG 10.0.2 | |
Linux Kernel | <6.2 | |
Linux Kernel | =6.2-rc1 | |
Linux Kernel | =6.2-rc2 | |
Linux Kernel | =6.2-rc3 | |
Linux Kernel | =6.2-rc4 | |
Linux Kernel | =6.2-rc5 | |
Linux Kernel | =6.2-rc6 | |
Fedoraproject Fedora | =38 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux | =9.0 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.11-1 6.12.12-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3161 is considered to have a high severity due to the potential for denial of service and undefined behavior in the Linux Kernel.
To fix CVE-2023-3161, update to a kernel version that is 6.2 or higher or apply the relevant patches provided by your distribution.
CVE-2023-3161 affects various versions of the Linux Kernel up to exclusive version 6.2 and also specific IBM Security Verify Governance components.
The impact of CVE-2023-3161 includes the possibility of denial of service due to a shift-out-of-bounds condition in the Framebuffer Console.
CVE-2023-3161 was disclosed in the year 2023, following the findings related to the Framebuffer Console in the Linux Kernel.