CVE-2023-3107

A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:freebsd:freebsd:12.4:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:rc2-p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:12.4:rc2-p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:b1-p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:b2-p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:p2:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:p3:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:p5:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:p6:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:p7:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:p8:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.1:rc1-p1:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.2:-:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:*

History

13 Feb 2025, 17:16

Type Values Removed Values Added
Summary (en) A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service. (en) A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.

21 Nov 2024, 08:16

Type Values Removed Values Added
References () https://security.FreeBSD.org/advisories/FreeBSD-SA-23:06.ipv6.asc - Mitigation, Vendor Advisory () https://security.FreeBSD.org/advisories/FreeBSD-SA-23:06.ipv6.asc - Mitigation, Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20230804-0001/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20230804-0001/ - Third Party Advisory
Summary
  • (es) Un conjunto de paquetes ipv6 cuidadosamente diseñados puede desencadenar un desbordamiento de enteros en el cálculo del campo de longitud de la carga útil de un paquete reensamblado por fragmentos. Esto permite a un atacante desencadenar un kernel panic, resultando en una denegación de servicio.

Information

Published : 2023-08-01 23:15

Updated : 2025-02-13 17:16


NVD link : CVE-2023-3107

Mitre link : CVE-2023-3107

CVE.ORG link : CVE-2023-3107


JSON object : View

Products Affected

freebsd

  • freebsd

netapp

  • clustered_data_ontap
CWE
CWE-190

Integer Overflow or Wraparound