CVE-2023-1074
MEDIUMLinux Kernel - Memory Leak in Stream Control Transmission Protocol
Title source: llmDescription
A memory leak flaw was found in the Linux kernel's Stream Control Transmission Protocol. This issue may occur when a user starts a malicious networking service and someone connects to this service. This could allow a local user to starve resources, causing a denial of service.
References (6)
Core 6
Core References
Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2173430
Mailing List, Patch
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=458e279f861d3f61796894cd158b780765a1569f
Mailing List, Third Party Advisory
https://www.openwall.com/lists/oss-security/2023/01/23/1
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html
Mailing List mailing-list
http://www.openwall.com/lists/oss-security/2023/11/05/4
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html
Scores
CVSS v3
5.5
EPSS
0.0024
EPSS Percentile
14.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (1)
linux/linux_kernel
Published
Mar 27, 2023
Tracked Since
Feb 18, 2026