CVE-2023-6356: Kernel: null pointer dereference in nvmet_tcp_build_iovec
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver and causing kernel panic and a denial of service.
Other sources
Linux Kernel is vulnerable to a denial of service, caused by a NULL pointer dereference flaw in the NVMe driver. By sending specially crafted TCP packages when using NVMe over TCP, a remote authenticated attacker could exploit this vulnerability to cause kernel panic, and results in a denial of service condition.
— IBM
There's a flaw in Linux kernel's NVMe driver where an attacker can send crafted TCP packets leading to NULL point dereference in nvmettcpbuildiovec. A successfully attack can result in a remote Denial-of-service.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6356?
CVE-2023-6356 is classified as a critical severity vulnerability due to its potential to cause a kernel panic and denial of service.
What versions are affected by CVE-2023-6356?
CVE-2023-6356 impacts specific versions of the Linux kernel and various IBM and Red Hat software components including versions up to and including ISVG 10.0.2.
How can I mitigate the effects of CVE-2023-6356?
To mitigate CVE-2023-6356, updating the Linux kernel and related software components to the latest patched versions is recommended.
Who is vulnerable to CVE-2023-6356?
Organizations using affected versions of the Linux kernel and IBM Security Verify Governance, Identity Manager products are vulnerable to CVE-2023-6356.
What exploits are associated with CVE-2023-6356?
CVE-2023-6356 allows unauthenticated attackers to exploit the vulnerability through crafted TCP packets to trigger a NULL pointer dereference.