CVE-2023-3338: Crash due to a null pointer dereference in the dn_nsp_send function

Published Jun 26, 2023
·
Updated

A flaw in the Linux Kernel found. While attempting to ping localhost by sending a Hello message to a local DECnet socket, Null Pointer Dereference happens in the dnnspsend function (net/decnet/dnnspout.c).

The bug happens only for systems where legacy code enabled (Kernel config param CONFIGDECNET), because the DECnet subsystem has been officially removed from all longterm and stable kernel series, starting from 4.14.319, 4.19.287, 5.4.248, 5.10.185 and 5.15.118.

Reference: https://seclists.org/oss-sec/2023/q2/276

Other sources

A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.

Affected Software

7 affected componentsFixes available
redhat/kernel<6.5
6.5
Linux Linux kernel=6.5-rc1
Linux Linux kernel<6.5
NetApp Active Iq Unified Manager Vsphere
Debian Debian Linux=10.0
Debian Debian Linux=11.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.133-16.12.22-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.133-1Fixed in 6.12.22-1
  2. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 6.5
  3. Upgrade

    Upgrade Linux kernel (DECnet/CONFIG_DECNET) to a version that resolves this vulnerability.

    Fixed in 4.14.319
  4. Upgrade

    Upgrade Linux kernel (DECnet/CONFIG_DECNET) to a version that resolves this vulnerability.

    Fixed in 4.19.287
  5. Upgrade

    Upgrade Linux kernel (DECnet/CONFIG_DECNET) to a version that resolves this vulnerability.

    Fixed in 5.4.248
  6. Upgrade

    Upgrade Linux kernel (DECnet/CONFIG_DECNET) to a version that resolves this vulnerability.

    Fixed in 5.10.185
  7. Upgrade

    Upgrade Linux kernel (DECnet/CONFIG_DECNET) to a version that resolves this vulnerability.

    Fixed in 5.15.118
  8. Configuration

    Disable legacy DECnet networking support (CONFIG_DECNET), since the issue triggers only when CONFIG_DECNET is enabled; DECnet is removed from longterm/stable kernel series starting from 4.14.319, 4.19.287, 5.4.248, 5.10.185 and 5.15.118.

    Linux kernel CONFIG_DECNET = disabled
  9. Compensating control

    If you cannot update immediately, prevent remote triggering of the crash by blocking access to DECnet networking (legacy DECnet support) at the network layer; the flaw can be exploited remotely to crash the system.

Event History

Jun 26, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeakness
Jun 29, 2023
Data Sourced
via Red Hat·04:58 PM
DescriptionSeverityAffected Software
Jun 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:20 AM
Description
Apr 12, 2025
Data Sourced
via Ubuntu·04:46 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-3338?

CVE-2023-3338 is classified as a high-severity vulnerability due to its potential impact on systems with legacy DECnet protocols enabled.

2

How do I fix CVE-2023-3338?

To mitigate CVE-2023-3338, update the Linux kernel to version 6.5 or any of the specified remedied versions for Debian systems.

3

Who is affected by CVE-2023-3338?

CVE-2023-3338 affects systems running specific versions of the Linux kernel, particularly those with DECnet legacy code enabled.

4

What systems are at risk from CVE-2023-3338?

Systems at risk from CVE-2023-3338 include those using Red Hat and Debian distributions with kernel versions prior to 6.5.

5

What type of issue is CVE-2023-3338?

CVE-2023-3338 is a null pointer dereference vulnerability occurring in the dn_nsp_send function of the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203