Tracker / CVE-2023-42754
CVE-2023-42754
Medium 5.5
A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs. This issue may allow a local user with CAP_NET_ADMIN privileges to crash the system.
Affected products and versions
| fedoraproject | fedora |
|---|---|
| linux | linux_kernel |
| linux | linux_kernel · … → 6.6 |
| redhat | enterprise_linux |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.