kernel CVE-2023-23454
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.13.0
Patched versions
1.13.0
kernel-5.15
(bottlerocket)
< 1.13.0
1.13.0
An out-of-bounds (OOB) read problem was found in cbq_classify in net/sched/sch_cbq.c in the Linux kernel. This issue may allow a local attacker to cause a denial of service due to type confusion. Non-negative numbers could indicate a TC_ACT_SHOT condition rather than valid classification results.