CVE-2023-1074: Medium severity Linux Linux kernel vulnerability

Published Feb 26, 2023
·
Updated

A flaw in the Linux Kernel found. Fail if no bound addresses can be used for a given scope. A type confusion can happen in inetdiagmsgsctpasocfill() in net/sctp/diag.c, which uses a type confused pointer to return information to userspace when issuing a listentry() on asoc->base.bindaddr.addresslist.next when the list is empty.

References: https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=458e279f861d3f61796894cd158b780765a1569f https://www.openwall.com/lists/oss-security/2023/01/23/1

Other sources

A memory leak flaw was found in the Linux kernel's Stream Control Transmission Protocol. This issue may occur when a user starts a malicious networking service and someone connects to this service. This could allow a local user to starve resources, causing a denial of service.

Launchpad

Linux Kernel is vulnerable to a denial of service, caused by a memory leak flaw in the Stream Control Transmission Protocol. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to starve resources, and results in a denial of service condition.

IBM

Affected Software

5 affected componentsFixes available
redhat/kernel<6.2
6.2
Linux Linux kernel
IBM Security Verify Governance, Identity Manager software component<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager virtual appliance component<=ISVG 10.0.2
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Feb 26, 2023
Data Sourced
via Red Hat·04:34 PM
DescriptionSeverityAffected Software
Mar 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:13 AM
Description
May 2, 2025
Data Sourced
via Ubuntu·05:20 AM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-1074?

CVE-2023-1074 has been classified as a critical vulnerability due to the potential for type confusion and its implications on system security.

2

Which software versions are affected by CVE-2023-1074?

CVE-2023-1074 affects various versions of the Linux Kernel, specifically those prior to 5.10.223-1, 5.10.226-1, 6.1.123-1, and 6.2, as well as specific IBM Security Verify Governance versions.

3

How do I fix CVE-2023-1074?

To fix CVE-2023-1074, upgrade your affected Linux Kernel to version 5.10.223-1, 5.10.226-1, 6.1.123-1, or 6.2.

4

What systems are impacted by CVE-2023-1074?

CVE-2023-1074 impacts systems utilizing the Linux Kernel and specific versions of IBM Security Verify Governance, Identity Manager components.

5

What is the nature of the vulnerability described in CVE-2023-1074?

CVE-2023-1074 is a type confusion vulnerability that occurs in the inet_diag_msg_sctpasoc_fill() function, potentially allowing unauthorized information to be returned to userspace.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203