Kernel: tap: tap_open(): correctly initialize socket uid next fix of i_uid to current_fsuid
CVE-2023-4194
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 7 August 2023
What is CVE-2023-4194?
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following upstream commits - a096ccca6e50 ("tun: tun_chr_open(): correctly initialize socket uid"), - 66b2c338adce ("tap: tap_open(): correctly initialize socket uid"), pass "inode->i_uid" to sock_init_data_uid() as the last parameter and that turns out to not be accurate.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat Enterprise Linux 9 0:5.14.0-362.8.1.el9_3
Red Hat Enterprise Linux 9 0:5.14.0-362.8.1.el9_3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved