
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-52698 is a memory leak vulnerability discovered in the Linux kernel's CALIPSO (Common Architecture Label IPv6 Security Option) netlink protocol implementation. The issue was identified when IPv6 support is disabled at boot (ipv6.disable=1), where the calipso_init() function's netlbl_calipso_ops_register() is not called, causing netlbl_calipso_ops_get() to return NULL. This vulnerability was found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) using the Syzkaller fuzzing tool (Kernel Git).
The vulnerability occurs in the netlbl_calipso_add_pass() function where memory is allocated for the doi_def variable but not properly freed with calipso_doi_free() when IPv6 is disabled. The issue manifests as a memory leak of 64 bytes, as demonstrated by the hex dump showing an unreferenced object at address 0xffff888011d68180. The vulnerability was introduced with the initial support for the CALIPSO netlink protocol (commit cb72d38211ea) (Kernel Git).
The vulnerability results in a memory leak that could lead to resource exhaustion over time, potentially causing system performance degradation or denial of service conditions (Kernel Git).
The vulnerability requires IPv6 to be disabled at boot time (using ipv6.disable=1) and can be triggered through the CALIPSO netlink protocol interface. The issue has been demonstrated using the Syzkaller fuzzing tool (Kernel Git).
The issue has been fixed in various Linux distributions through security updates. For example, Debian 10 (Buster) has addressed this in linux-5.10 version 5.10.209-2~deb10u1 and linux version 4.19.316-1 (Debian LTS). Ubuntu has also released fixes in their security updates (Ubuntu Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."