Vulnerability Intelligence Report
Kernel: tun: bugs for oversize packet when napi frags enabled in tun_napi_alloc_frags
CVE-2023-3812
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.34%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-787 ↗Out-of-bounds Write
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.18.0-513.9.1.rt7.311.el8_9 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.18.0-513.9.1.el8_9 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | all |
| Red Hat | Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | all |
| Red Hat | Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | 0:4.18.0-147.94.1.el8_1 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | 0:4.18.0-193.133.1.el8_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | 0:4.18.0-193.133.1.rt13.184.el8_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | 0:4.18.0-193.133.1.el8_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | all |
| Red Hat | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | 0:4.18.0-193.133.1.el8_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:4.18.0-305.120.1.el8_4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | 0:4.18.0-305.120.1.rt7.196.el8_4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | 0:4.18.0-305.120.1.el8_4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | 0:4.18.0-305.120.1.el8_4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | all |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | all |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | 0:4.18.0-372.87.1.el8_6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | all |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | 0:4.18.0-477.43.1.el8_8 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | 0:5.14.0-362.18.1.el9_3 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | all |
| Red Hat | Red Hat Enterprise Linux 9 | 0:5.14.0-362.18.1.el9_3 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:5.14.0-70.80.1.el9_0 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:5.14.0-70.80.1.rt21.151.el9_0 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | all |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 0:5.14.0-284.40.1.el9_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 0:5.14.0-284.40.1.rt14.325.el9_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | all |
| Red Hat | Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | 0:4.18.0-372.87.1.el8_6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 6 | all |
| Red Hat | Red Hat Enterprise Linux 7 | all |
| Red Hat | Red Hat Enterprise Linux 7 | all |
| Red Hat | Red Hat Enterprise Linux 9 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.344%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2023-07-20T13:02:44 |
| Published | 2023-07-24T15:19:21 |
| Patch Date | 2022-10-22 |
| Last Updated | 2026-02-26T20:27:31 |
Community Chatter & Buzz