CVE-2023-2156

Public on 2023-05-09
Modified on 2024-04-22
Description
A flaw was found in the Linux kernel's networking subsystem within the RPL protocol's handling. This issue results from the improper handling of user-supplied data, which can lead to an assertion failure. This flaw allows an unauthenticated, remote attacker to create a denial of service condition on the system.
Severity
Important severity
Important
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 kernel Not Affected
Amazon Linux 2 - Core kernel Not Affected
Amazon Linux 2 - Kernel-5.4 Extra kernel Not Affected
Amazon Linux 2 - Kernel-5.10 Extra kernel 2023-06-21 ALAS2KERNEL-5.10-2023-034 Fixed
Amazon Linux 2 - Kernel-5.15 Extra kernel 2023-06-21 ALAS2KERNEL-5.15-2023-021 Fixed
Amazon Linux 2023 kernel 2023-06-21 ALAS2023-2023-228 Fixed
Amazon Linux 2 - Livepatch Extra kernel-livepatch-5.10.177-158.645 2023-08-17 ALAS2LIVEPATCH-2023-141 Fixed
Amazon Linux 2 - Livepatch Extra kernel-livepatch-5.10.178-162.673 2023-08-17 ALAS2LIVEPATCH-2023-140 Fixed
Amazon Linux 2 - Livepatch Extra kernel-livepatch-5.10.179-166.674 2023-08-17 ALAS2LIVEPATCH-2023-139 Fixed
Amazon Linux 2 - Livepatch Extra kernel-livepatch-5.10.179-168.710 2023-08-17 ALAS2LIVEPATCH-2023-138 Fixed
Amazon Linux 2 - Livepatch Extra kernel-livepatch-5.10.179-171.711 2023-08-17 ALAS2LIVEPATCH-2023-137 Fixed
Amazon Linux 2023 kernel-livepatch-6.1.25-37.47 2023-09-15 ALAS2023LIVEPATCH-2023-019 Fixed
Amazon Linux 2023 kernel-livepatch-6.1.27-43.48 2023-09-15 ALAS2023LIVEPATCH-2023-016 Fixed
Amazon Linux 2023 kernel-livepatch-6.1.29-47.49 2023-09-15 ALAS2023LIVEPATCH-2023-017 Fixed
Amazon Linux 2023 kernel-livepatch-6.1.29-50.88 2023-09-15 ALAS2023LIVEPATCH-2023-018 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H