Bug 1211906 (CVE-2023-3022)

Summary: VUL-0: CVE-2023-3022: kernel-source-rt,kernel-source,kernel-source-azure: panic in fib6_rule_suppress+0x22 for IPv6 when fib6_rule_lookup fails
Product: [Novell Products] SUSE Security Incidents Reporter: Gabriele Sonnu <gabriele.sonnu>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED INVALID QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P5 - None CC: security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/368014/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Gabriele Sonnu 2023-06-01 10:00:27 UTC
CVE-2023-3022

A flaw in the Linux Kernel found. If IPV6 being used in the way that some specific networking local rule enabled and both IPV6 being used, then it can lead to Kernel crash with the message "fib6_rule_suppress+0x22". It happens when receiving some networking packet to the local IPV6 address that matches this specific rule.

References:
https://github.com/torvalds/linux/commit/a65120bae4b7
https://bugzilla.redhat.com/show_bug.cgi?id=2175952
https://bugzilla.redhat.com/show_bug.cgi?id=2167604
https://bugzilla.redhat.com/show_bug.cgi?id=2140599#c13

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3022
https://bugzilla.redhat.com/show_bug.cgi?id=2211440
Comment 1 Gabriele Sonnu 2023-06-01 10:01:04 UTC
Already fixed, closing.