CVE-2023-49062
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packet generation. After a bpf_xdp_adjust_head call, Katran code didnโt initialize the Identification field for the IPv4 header, resulting in writing content of kernel memory in that field of IP header. The issue affected all Katran versions prior to commit 6a03106ac1eab39d0303662963589ecb2374c97f
| Vendor | |
| Product | katran |
| Published | Nov 28, 2023 |
| Last Updated | Aug 2, 2024 |
Stay Ahead of the Next One
Get instant alerts for facebook katran
Be the first to know when new unknown vulnerabilities affecting facebook katran are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Facebook / Katran
0 < 6a03106ac1eab39d0303662963589ecb2374c97f