CVE-2023-35788: High severity IBM QRadar SIEM vulnerability
An issue was discovered in flsetgeneveopt in net/sched/clsflower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCAFLOWERKEYENCOPTSGENEVE packets. This may result in denial of service or privilege escalation.
Other sources
Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by an off-by-one flaw in the flsetgeneveopt fucntion. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges or cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.4 - Upgrade
Upgrade
linux kernelto a version that resolves this vulnerability.Fixed in 6.3.7Patch 4d56304e5827c8cc8cc18c75343d283af7c4825c
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35788?
CVE-2023-35788 has a severity level that can lead to denial of service or privilege escalation.
How do I fix CVE-2023-35788?
To fix CVE-2023-35788, you should upgrade the Linux kernel to version 6.3.7 or later.
Which versions of the Linux kernel are affected by CVE-2023-35788?
CVE-2023-35788 affects the Linux kernel versions prior to 6.3.7, including various versions between 4.19 and 6.3.
Is CVE-2023-35788 relevant to IBM QRadar SIEM?
Yes, CVE-2023-35788 affects IBM QRadar SIEM versions up to 7.5.0 UP7.
What are the potential impacts of CVE-2023-35788?
CVE-2023-35788 can lead to out-of-bounds writes, resulting in potential denial of service or privilege escalation.