Description
atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).
References
https://www.debian.org/security/2023/dsa-5324
Third Party Advisory
https://www.openwall.com/lists/oss-security/2023/01/10/1
Mailing ListThird Party Advisory
https://www.openwall.com/lists/oss-security/2023/01/10/4
Mailing ListThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
5.5 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2023-01-12T07:15:09.953
2 years agoLast modified
2023-05-03T14:15:31.450
2 years ago