CVE-2023-52889: apparmor: Fix null pointer deref when receiving skb during sock creation
apparmor: Fix null pointer deref when receiving skb during sock creation
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52889?
CVE-2023-52889 has a severity rating that indicates it could lead to a null pointer dereference in the Linux kernel when processing certain ICMP packets.
How do I fix CVE-2023-52889?
To fix CVE-2023-52889, upgrade to the latest kernel version that contains the patches, specifically 5.10.226-1, 6.1.123-1, or other specified remedy versions.
What versions of the Linux kernel are affected by CVE-2023-52889?
CVE-2023-52889 affects Linux kernel versions between 4.20 and 5.4.282, 5.5 and 5.10.224, 5.11 and 5.15.165, 5.16 and 6.1.103, 6.2 and 6.6.44, and 6.7 and 6.10.3.
What types of systems are impacted by CVE-2023-52889?
Any system running an affected version of the Linux kernel that processes ICMP packets with secmark set while creating an ICMP raw socket is at risk.
Is there a workaround for CVE-2023-52889?
Currently, the recommended approach is to apply the kernel updates released to address CVE-2023-52889, as there is no known workaround.