CVE-2023-52340
HIGHLinux Kernel < 6.3 - Denial of Service via IPv6 Route Consumption
Title source: llmDescription
The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of service (network is unreachable errors) when IPv6 packets are sent in a loop via a raw socket.
References (5)
Core 5
Core References
Mailing List, Patch
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3
Mailing List, Patch
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=af6d10345ca76670c1b7c37799f0d5576ccef277
Vendor Advisory
https://security.netapp.com/advisory/ntap-20240816-0005/
Scores
CVSS v3
7.5
EPSS
0.0095
EPSS Percentile
56.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (1)
linux/linux_kernel
< 6.3
Published
Jul 05, 2024
Tracked Since
Feb 18, 2026