CVE-2023-6200

HIGH

Linux Kernel - Unauthenticated Remote Code Execution via ICMPv6 Router Advertisement Race Condition

Title source: llm
STIX 2.1

Description

A race condition was found in the Linux Kernel. Under certain conditions, an unauthenticated attacker from an adjacent network could send an ICMPv6 router advertisement packet, causing arbitrary code execution.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2023-6200
Issue Tracking, Patch issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2250377

Scores

CVSS v3 7.5
EPSS 0.0215
EPSS Percentile 79.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-362
Status published
Products (2)
linux/linux_kernel 6.7 rc1 (6 CPE variants)
linux/linux_kernel < 6.7
Published Jan 28, 2024
Tracked Since Feb 18, 2026