CVE-2023-2156: Debian Linux
High severity, CVSS 7.5. EPSS: 6.1% chance of exploitation in the next 30 days.
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 38 only
- Linux Linux Kernel: from 5.7, before 5.10.184 (fixed in 5.10.184); from 5.11, before 5.15.117 (fixed in 5.15.117); from 5.16, before 6.1.34 (fixed in 6.1.34); from 6.2, before 6.2.13 (fixed in 6.2.13); from 6.3, before 6.3.8 (fixed in 6.3.8)
- Red Hat Enterprise Linux: version 9.0 only
Published 2023-05-09. Last modified 2026-06-17.