Kernel crash via buffer split (OpenBSD 7.3/7.4 pre-errata)
CVE-2023-52558 Published on March 1, 2024
OpenBSD 7.4 and 7.3 m_split() network buffer kernel crash
In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.
Vulnerability Analysis
CVE-2023-52558 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Incorrect Calculation of Buffer Size
The software does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Products Associated with CVE-2023-52558
Want to know whenever a new CVE is published for OpenBSD? stack.watch will email you.
Affected Versions
OpenBSD:- Version 7.3 and below 7.3 errata 019 is affected.
- Version 7.4 and below 7.4 errata 002 is affected.
- Version 7.3 and below 7.3_errata_019 is affected.
- Version 7.4 and below 7.4_errata_002 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.