Bug 1211906 (CVE-2023-3022) - VUL-0: CVE-2023-3022: kernel-source-rt,kernel-source,kernel-source-azure: panic in fib6_rule_suppress+0x22 for IPv6 when fib6_rule_lookup fails
Summary: VUL-0: CVE-2023-3022: kernel-source-rt,kernel-source,kernel-source-azure: pan...
Status: RESOLVED INVALID
Alias: CVE-2023-3022
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/368014/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-01 10:00 UTC by Gabriele Sonnu
Modified: 2023-06-01 10:01 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gabriele Sonnu 2023-06-01 10:00:27 UTC
CVE-2023-3022

A flaw in the Linux Kernel found. If IPV6 being used in the way that some specific networking local rule enabled and both IPV6 being used, then it can lead to Kernel crash with the message "fib6_rule_suppress+0x22". It happens when receiving some networking packet to the local IPV6 address that matches this specific rule.

References:
https://github.com/torvalds/linux/commit/a65120bae4b7
https://bugzilla.redhat.com/show_bug.cgi?id=2175952
https://bugzilla.redhat.com/show_bug.cgi?id=2167604
https://bugzilla.redhat.com/show_bug.cgi?id=2140599#c13

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3022
https://bugzilla.redhat.com/show_bug.cgi?id=2211440
Comment 1 Gabriele Sonnu 2023-06-01 10:01:04 UTC
Already fixed, closing.