๐Ÿ” CVE Alert

CVE-2023-49062

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packet generation. After a bpf_xdp_adjust_head call, Katran code didnโ€™t initialize the Identification field for the IPv4 header, resulting in writing content of kernel memory in that field of IP header. The issue affected all Katran versions prior to commit 6a03106ac1eab39d0303662963589ecb2374c97f

Vendor facebook
Product katran
Published Nov 28, 2023
Last Updated Aug 2, 2024
Stay Ahead of the Next One

Get instant alerts for facebook katran

Be the first to know when new unknown vulnerabilities affecting facebook katran are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Facebook / Katran
0 < 6a03106ac1eab39d0303662963589ecb2374c97f

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
facebook.com: https://www.facebook.com/security/advisories/cve-2023-49062 github.com: https://github.com/facebookincubator/katran/commit/6a03106ac1eab39d0303662963589ecb2374c97f