CVE-2024-23849

Public on 2024-01-23
Modified on 2024-03-01
Description

In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access.

Severity
Important
See what this means
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory
HAQM Linux 1 kernel 2024-03-04 ALAS-2024-1923
HAQM Linux 2 - Core kernel 2024-03-04 ALAS2-2024-2475
HAQM Linux 2 - Kernel-5.10 Extra kernel 2024-02-05 ALAS2KERNEL-5.10-2024-048
HAQM Linux 2 - Kernel-5.15 Extra kernel 2024-02-20 ALAS2KERNEL-5.15-2024-038
HAQM Linux 2 - Kernel-5.4 Extra kernel 2024-02-05 ALAS2KERNEL-5.4-2024-059
HAQM Linux 2023 kernel 2024-02-19 ALAS2023-2024-517
HAQM Linux 2 - Livepatch Extra kernel-livepatch-4.14.336-253.554 2024-02-20 ALAS2LIVEPATCH-2024-165
HAQM Linux 2 - Livepatch Extra kernel-livepatch-5.10.201-191.748 2024-03-06 ALAS2LIVEPATCH-2024-167
HAQM Linux 2 - Livepatch Extra kernel-livepatch-5.10.205-195.804 2024-03-06 ALAS2LIVEPATCH-2024-169
HAQM Linux 2 - Livepatch Extra kernel-livepatch-5.10.205-195.807 2024-03-06 ALAS2LIVEPATCH-2024-166

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H