CVE-2023-3268: High severity Linux Linux kernel vulnerability
An out of bounds (OOB) memory access flaw was found in the Linux kernel in relayfilereadstartpos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.
Other sources
Linux Kernel is vulnerable to a denial of service, caused by an out-of-bounds memory access flaw in the relayfilereadstartpos function in kernel/relay.c in the relayfs. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause the system to crash or obtain sensitive information.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/Kernelto a version that resolves this vulnerability.Fixed in 6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3268?
CVE-2023-3268 is classified as a high severity vulnerability due to its potential to crash systems and leak sensitive kernel information.
How do I fix CVE-2023-3268?
To fix CVE-2023-3268, update the Linux kernel to versions 6.4 or apply specific patches if using prior versions.
Who is affected by CVE-2023-3268?
CVE-2023-3268 affects systems running vulnerable versions of the Linux kernel, particularly those below version 6.4.
What type of vulnerability is CVE-2023-3268?
CVE-2023-3268 is an out of bounds memory access vulnerability found in the relayfs of the Linux kernel.
Can CVE-2023-3268 be exploited remotely?
CVE-2023-3268 requires local access for exploitation, meaning a local attacker could leverage the vulnerability.