imPC@ndo IT

Tracker / CVE-2023-1390

CVE-2023-1390

High 7.5

A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packets to a system with a UDP bearer results in the CPU utilization for the system to instantly spike to 100%, causing a denial of service condition.

Affected products and versions

linux linux_kernel
linux linux_kernel · 4.10 → 4.14.217
linux linux_kernel · 4.15 → 4.19.170
linux linux_kernel · 4.20 → 5.4.92
linux linux_kernel · 4.3 → 4.9.253
linux linux_kernel · 5.5 → 5.10.10

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References