← Back to CVE List
Vulnerability Intelligence Report
Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags

CVE-2023-3812

An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.34%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-787 ↗Out-of-bounds Write

Affected Products & Versions

Vendor Product Affected Versions
Red Hat Red Hat Enterprise Linux 8 0:4.18.0-513.9.1.rt7.311.el8_9 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8 0:4.18.0-513.9.1.el8_9 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8 all
Red Hat Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions all
Red Hat Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions 0:4.18.0-147.94.1.el8_1 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support 0:4.18.0-193.133.1.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Telecommunications Update Service 0:4.18.0-193.133.1.rt13.184.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Telecommunications Update Service 0:4.18.0-193.133.1.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions all
Red Hat Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions 0:4.18.0-193.133.1.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:4.18.0-305.120.1.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service 0:4.18.0-305.120.1.rt7.196.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service 0:4.18.0-305.120.1.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions 0:4.18.0-305.120.1.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions all
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support all
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support 0:4.18.0-372.87.1.el8_6 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support all
Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support 0:4.18.0-477.43.1.el8_8 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9 0:5.14.0-362.18.1.el9_3 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9 all
Red Hat Red Hat Enterprise Linux 9 0:5.14.0-362.18.1.el9_3 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support 0:5.14.0-70.80.1.el9_0 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support 0:5.14.0-70.80.1.rt21.151.el9_0 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support all
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:5.14.0-284.40.1.el9_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:5.14.0-284.40.1.rt14.325.el9_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support all
Red Hat Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 0:4.18.0-372.87.1.el8_6 < * (unaffected)
Red Hat Red Hat Enterprise Linux 6 all
Red Hat Red Hat Enterprise Linux 7 all
Red Hat Red Hat Enterprise Linux 7 all
Red Hat Red Hat Enterprise Linux 9 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.344%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2023-07-20T13:02:44
Published2023-07-24T15:19:21
Patch Date2022-10-22
Last Updated2026-02-26T20:27:31

LINK COPIED TO CLIPBOARD