CVE-2023-0179

NameCVE-2023-0179
DescriptionA buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3349-1, DSA-5324-1, ELA-810-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)jessie, jessie (lts)3.16.84-1vulnerable
stretch (security)4.9.320-2vulnerable
stretch (lts), stretch4.9.320-3vulnerable
buster4.19.249-2fixed
buster (security)4.19.304-1fixed
bullseye5.10.209-2fixed
bullseye (security)5.10.205-2fixed
bookworm6.1.76-1fixed
bookworm (security)6.1.69-1fixed
trixie, sid6.6.15-2fixed
linux-5.10 (PTS)stretch (lts), stretch5.10.205-2~deb9u1fixed
buster (security)5.10.209-2~deb10u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcejessie(unfixed)end-of-life
linuxsourcestretch(unfixed)end-of-life
linuxsourcebuster(not affected)
linuxsourcebullseye5.10.162-1DSA-5324-1
linuxsource(unstable)6.1.7-1
linux-5.10sourcestretch5.10.162-1~deb9u1ELA-810-1
linux-5.10sourcebuster5.10.162-1~deb10u1DLA-3349-1

Notes

[buster] - linux <not-affected> (Vulnerable code not present)
https://www.openwall.com/lists/oss-security/2023/01/13/2
https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230111212251.193032-4-pablo@netfilter.org/

Search for package or bug name: Reporting problems