kernel CVE-2023-35788
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.14.2
Patched versions
1.14.2
kernel-5.15
(bottlerocket)
< 1.14.2
1.14.2
An issue was discovered in
fl_set_geneve_opt
innet/sched/cls_flower.c
. It allows an out-of-bounds write in the flower classifier code viaTCA_FLOWER_KEY_ENC_OPTS_GENEVE
packets. This may result in denial of service or privilege escalation.