CVE-2023-4128: Fixes in Linux Kernel
Published Jul 25, 2023
·Updated
** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-4206, CVE-2023-4207, CVE-2023-4208. Reason: This record is a duplicate of CVE-2023-4206, CVE-2023-4207, CVE-2023-4208. Notes: All CVE users should reference CVE-2023-4206, CVE-2023-4207, CVE-2023-4208 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.
Affected Software
21 affected componentsFixes available
redhat/kernel<0:4.18.0-147.90.1.el8_1
0:4.18.0-147.90.1.el8_1
redhat/kernel<0:4.18.0-193.116.1.el8_2
0:4.18.0-193.116.1.el8_2
redhat/kernel-rt<0:4.18.0-193.116.1.rt13.167.el8_2
0:4.18.0-193.116.1.rt13.167.el8_2
redhat/kernel<0:4.18.0-305.108.1.el8_4
0:4.18.0-305.108.1.el8_4
redhat/kernel<0:4.18.0-372.75.1.el8_6
0:4.18.0-372.75.1.el8_6
redhat/kernel<0:5.14.0-70.75.1.el9_0
0:5.14.0-70.75.1.el9_0
redhat/kernel-rt<0:5.14.0-70.75.1.rt21.146.el9_0
0:5.14.0-70.75.1.rt21.146.el9_0
redhat/Kernel<6.5
6.5
Linux Linux kernel<6.5
Linux Linux kernel=6.5
Linux Linux kernel=6.5-rc1
Linux Linux kernel=6.5-rc2
Linux Linux kernel=6.5-rc3
Linux Linux kernel=6.5-rc4
Fedoraproject Fedora=37
Fedoraproject Fedora=38
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
IBM Security Verify Governance, Identity Manager software component<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager virtual appliance component<=ISVG 10.0.2
Remediation
Information
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Mitigation
If not needed, disable the ability for unprivileged users
to create namespaces. To do this temporarily, do:
sudo sysctl -w kernel.unprivileged_userns_clone=0
To disable across reboots, do:
echo kernel.unprivileged_userns_clone=0 | \
sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf
Event History
Jul 25, 2023
Data Sourced
via Red Hat·12:37 PM
DescriptionSeverityAffected Software
Jul 29, 2023
CVE Published
12:00 AM
Aug 10, 2023
Rejected
04:50 PM
Data Sourced
05:15 PM
Description
Aug 25, 2023
Data Sourced
12:00 AM
SeverityWeakness
Nov 14, 2023
Rejected
via NVD·12:15 PM
Jan 12, 2024
Data Sourced
via Launchpad·12:25 AM
Description
Jan 16, 2024
Data Sourced
via Debian·12:27 AM
DescriptionAffected Software
Sep 16, 2024
Data Sourced
via Ubuntu·04:16 AM
RemedyDescriptionSeverityAffected Software