PT-2023-2733 · Linux+7 · Linux Kernel+7

·

CVE-2023-2156

·

Published

2023-05-04

·

Updated

2026-08-27

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the networking subsystem of the Linux kernel, specifically within the IPv6 RPL (Routing Protocol for Low-Power and Lossy Networks) protocol implementation. The issue occurs due to improper handling of user-supplied data and incorrect calculation of the packet header size in the ipv6 rpl segdata pos() function located in the net/ipv6/rpl.c module. This can lead to an assertion failure, allowing an unauthenticated remote attacker to cause a kernel crash and a denial of service condition by sending specially crafted IPv6 packets. This protocol is typically disabled by default in most distributions and is primarily used in embedded devices operating in wireless networks with high packet loss.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, disable support for the RPL protocol to minimize the risk of exploitation.

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8461
ALT-PU-2024-4263
ALT-PU-2024-4843
BDU:2023-02580
CVE-2023-2156
DLA-3512-1
DSA-5448-1
DSA-5453-1
MGASA-2023-0201
MGASA-2023-0202
OPENSUSE-SU-2023_2646-1
OPENSUSE-SU-2023_2871-1
OPENSUSE-SU-2023_3302-1
OPENSUSE-SU-2023_3311-1
OPENSUSE-SU-2023_3313-1
OPENSUSE-SU-2023_3318-1
OPENSUSE-SU-2023_3376-1
OPENSUSE-SU-2023_3377-1
OPENSUSE-SU-2023_3391-1
OPENSUSE-SU-2023_3630-1
OPENSUSE-SU-2023_3644-1
OPENSUSE-SU-2023_3647-1
OPENSUSE-SU-2023_3648-1
OPENSUSE-SU-2023_3653-1
OPENSUSE-SU-2023_3657-1
OPENSUSE-SU-2023_3658-1
OPENSUSE-SU-2023_3659-1
OPENSUSE-SU-2023_3671-1
OPENSUSE-SU-2023_3676-1
RHSA-2023:6583
RHSA-2023_6583
ROSA-SA-2023-2189
SUSE-SU-2023:2500-1
SUSE-SU-2023:2502-1
SUSE-SU-2023:2611-1
SUSE-SU-2023:2646-1
SUSE-SU-2023:2653-1
SUSE-SU-2023:2782-1
SUSE-SU-2023:2809-1
SUSE-SU-2023:2871-1
SUSE-SU-2023:3302-1
SUSE-SU-2023:3311-1
SUSE-SU-2023:3313-1
SUSE-SU-2023:3318-1
SUSE-SU-2023:3376-1
SUSE-SU-2023:3377-1
SUSE-SU-2023:3391-1
SUSE-SU-2023:3421-1
SUSE-SU-2023:3594-1
SUSE-SU-2023:3595-1
SUSE-SU-2023:3607-1
SUSE-SU-2023:3623-1
SUSE-SU-2023:3627-1
SUSE-SU-2023:3628-1
SUSE-SU-2023:3630-1
SUSE-SU-2023:3631-1
SUSE-SU-2023:3632-1
SUSE-SU-2023:3644-1
SUSE-SU-2023:3647-1
SUSE-SU-2023:3648-1
SUSE-SU-2023:3653-1
SUSE-SU-2023:3657-1
SUSE-SU-2023:3658-1
SUSE-SU-2023:3659-1
SUSE-SU-2023:3668-1
SUSE-SU-2023:3671-1
SUSE-SU-2023:3675-1
SUSE-SU-2023:3676-1
SUSE-SU-2023:3677-1
USN-6173-1
USN-6412-1
USN-6416-1
USN-6416-2
USN-6416-3
USN-6445-1
USN-6445-2
USN-6466-1
ZDI-23-547

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu