CVE-2023-2177

Updated on 20 Apr 2023

Severity

5.5 Medium severity

Details

CVSS score
5.5
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If stream_in allocation is failed, stream_out is freed which would further be accessed. A local user could use this flaw to crash the system or potentially cause a denial of service.

Details

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
AlmaLinux 8 Will Not Fix
Amazon Linux 2 5.10 Will Not Fix
Amazon Linux 2 5.4 Will Not Fix
Debian 11 Will Not Fix
RHEL 8 Will Not Fix
RHEL8 EUS 8.6 Released
9 kernels
  • 4.18.0-372.36.1.el8_6
  • 4.18.0-372.41.1.el8_6
  • 4.18.0-372.46.1.el8_6
  • 4.18.0-372.51.1.el8_6
  • 4.18.0-372.70.1.el8_6
  • 4.18.0-372.57.1.el8_6
  • 4.18.0-372.52.1.el8_6
  • 4.18.0-372.64.1.el8_6
  • 4.18.0-372.75.1.el8_6
RHEL 9 Will Not Fix
Rocky Linux 8 Will Not Fix
Ubuntu 20.04 Will Not Fix
Ubuntu 20.04 AWS Will Not Fix
Ubuntu 22.04 Will Not Fix
Ubuntu 22.04 AWS Will Not Fix
Ubuntu 22.04 Azure Will Not Fix