CVE-2023-35788: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only; version 22.04 only
- Debian Debian Linux: version 12.0 only; version 10.0 only; version 11.0 only
- Linux Linux Kernel: from 4.19, before 4.19.285 (fixed in 4.19.285); from 4.20, before 5.4.246 (fixed in 5.4.246); from 5.5, before 5.10.183 (fixed in 5.10.183); from 5.11, before 5.15.116 (fixed in 5.15.116); from 5.16, before 6.1.33 (fixed in 6.1.33); from 6.2, before 6.3.7 (fixed in 6.3.7)
- Netapp h300s Firmware: affected versions not specified
- Netapp h410c Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
Published 2023-06-16. Last modified 2026-06-17.