Crash due to a null pointer dereference in the dn_nsp_send function
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 8.0%
exploitation probability
8.0%top 5% of all CVEs
observed exploitation
nono source reports it
A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
Fedora · Fedoran/a · kernelRed Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9References
https://access.redhat.com/security/cve/CVE-2023-3338https://bugzilla.redhat.com/show_bug.cgi?id=2218618https://lists.debian.org/debian-lts-announce/2023/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00027.htmlhttps://seclists.org/oss-sec/2023/q2/276https://security.netapp.com/advisory/ntap-20230824-0005/https://www.debian.org/security/2023/dsa-5480