An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
2023-06-16T21:15:09.340
2025-05-05T16:15:41.317
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 4.19.285 | Yes |
Operating System | linux | linux_kernel | < 5.4.246 | Yes |
Operating System | linux | linux_kernel | < 5.10.183 | Yes |
Operating System | linux | linux_kernel | < 5.15.116 | Yes |
Operating System | linux | linux_kernel | < 6.1.33 | Yes |
Operating System | linux | linux_kernel | < 6.3.7 | Yes |
Operating System | debian | debian_linux | 12.0 | Yes |
Hardware | netapp | h300s | - | No |
Operating System | netapp | h300s_firmware | - | Yes |
Hardware | netapp | h500s | - | No |
Operating System | netapp | h500s_firmware | - | Yes |
Hardware | netapp | h700s | - | No |
Operating System | netapp | h700s_firmware | - | Yes |
Hardware | netapp | h410s | - | No |
Operating System | netapp | h410s_firmware | - | Yes |
Hardware | netapp | h410c | - | No |
Operating System | netapp | h410c_firmware | - | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 20.04 | Yes |
Operating System | canonical | ubuntu_linux | 22.04 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |