CVE-2023-52556: OpenBSD 7.4 pf state race condition kernel crash
Published Mar 1, 2024
·Updated
In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.
Affected Software
11 affected components
OpenBSD OpenBSD<7.4
OpenBSD OpenBSD<7.4
OpenBSD OpenBSD=7.4
OpenBSD OpenBSD=7.4-errata_001
OpenBSD OpenBSD=7.4-errata_002
OpenBSD OpenBSD=7.4-errata_003
OpenBSD OpenBSD=7.4-errata_004
OpenBSD OpenBSD=7.4-errata_005
OpenBSD OpenBSD=7.4-errata_006
OpenBSD OpenBSD=7.4-errata_007
OpenBSD OpenBSD=7.4-errata_008
Remediation
Event History
Mar 1, 2024
CVE Published
via MITRE·04:08 PM
Data Sourced
via MITRE·04:08 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-52556?
CVE-2023-52556 has a high severity rating due to its potential to cause kernel panic.
2
How do I fix CVE-2023-52556?
To fix CVE-2023-52556, apply the errata patch 009 provided by OpenBSD for version 7.4.
3
What systems are affected by CVE-2023-52556?
CVE-2023-52556 affects OpenBSD 7.4 before errata 009.
4
What type of vulnerability is CVE-2023-52556?
CVE-2023-52556 is a race condition vulnerability in pf(4) processing.
5
What are the potential consequences of CVE-2023-52556?
The potential consequences of CVE-2023-52556 include system instability leading to kernel panic.