PT-2023-2733 · Linux+7 · Linux Kernel+7
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the networking subsystem of the Linux kernel, specifically within the IPv6 RPL (Routing Protocol for Low-Power and Lossy Networks) protocol implementation. The issue occurs due to improper handling of user-supplied data and incorrect calculation of the packet header size in the
ipv6 rpl segdata pos() function located in the net/ipv6/rpl.c module. This can lead to an assertion failure, allowing an unauthenticated remote attacker to cause a kernel crash and a denial of service condition by sending specially crafted IPv6 packets. This protocol is typically disabled by default in most distributions and is primarily used in embedded devices operating in wireless networks with high packet loss.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, disable support for the RPL protocol to minimize the risk of exploitation.
DoS
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu