CVE-2023-2156: Debian Linux

High severity, CVSS 7.5. EPSS: 6.1% chance of exploitation in the next 30 days.

A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 38 only
  • Linux Linux Kernel: from 5.7, before 5.10.184 (fixed in 5.10.184); from 5.11, before 5.15.117 (fixed in 5.15.117); from 5.16, before 6.1.34 (fixed in 6.1.34); from 6.2, before 6.2.13 (fixed in 6.2.13); from 6.3, before 6.3.8 (fixed in 6.3.8)
  • Red Hat Enterprise Linux: version 9.0 only

Published 2023-05-09. Last modified 2026-06-17.