CVE-2023-49062
Last modified
CVE-2023-49062 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packet generation. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packet generation. After a bpf_xdp_adjust_head call, Katran code didn’t initialize the Identification field for the IPv4 header, resulting in writing content of kernel memory in that field of IP header. The issue affected all Katran versions prior to commit 6a03106ac1eab39d0303662963589ecb2374c97f
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Katran | < 2023-11-15 |
References
- https://www.facebook.com/security/advisories/cve-2023-49062Vendor Advisory
- https://www.facebook.com/security/advisories/cve-2023-49062Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-49062?
How severe is CVE-2023-49062?
How do I fix CVE-2023-49062?
Are you affected by CVE-2023-49062?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
