CVE-2023-23455: Medium severity IBM Security Verify Governance, Identity Manager software component vulnerability
A denial of service flaw was found in atmtcenqueue in net/sched/schatm.c in the Linux kernel. In this flaw a local attacker may cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TCACTSHOT condition rather than valid classification results).
Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a2965c7be0522eaa18808684b7b82b248515511b
Other sources
atmtcenqueue in net/sched/schatm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TCACTSHOT condition rather than valid classification results).
— Launchpad
Linux Kernel is vulnerable to a denial of service, caused by a type confusion flaw in the atmtcenqueue function in net/sched/schatm.c. By sending a specially-crafted request, a local attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23455?
CVE-2023-23455 is classified as a denial of service vulnerability in the Linux kernel.
How do I fix CVE-2023-23455?
To fix CVE-2023-23455, update the Linux kernel to version 6.2 or above.
What software is affected by CVE-2023-23455?
CVE-2023-23455 affects various versions of the Linux kernel, IBM Security Verify Governance, and Identity Manager software components.
Can CVE-2023-23455 be exploited locally?
Yes, CVE-2023-23455 can be exploited by a local attacker, potentially leading to a denial of service.
What specific Linux kernel versions contain CVE-2023-23455?
CVE-2023-23455 impacts Linux kernel versions from 2.6.12 up to 6.1.4.