Skip to content

kernel CVE-2023-23454

Moderate
rpkelly published GHSA-7xv9-9rj8-9g9f Mar 21, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.13.0

Patched versions

1.13.0
kernel-5.15 (bottlerocket)
< 1.13.0
1.13.0

Description

An out-of-bounds (OOB) read problem was found in cbq_classify in net/sched/sch_cbq.c in the Linux kernel. This issue may allow a local attacker to cause a denial of service due to type confusion. Non-negative numbers could indicate a TC_ACT_SHOT condition rather than valid classification results.

Severity

Moderate

CVE ID

CVE-2023-23454

Weaknesses

No CWEs