CVE-2023-42754 - CVE House
Back to Database
Status published Medium CVE-2023-42754

Kernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()

Vulnerability Description

A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs. This issue may allow a local user with CAP_NET_ADMIN privileges to crash the system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-42754

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7
Vulnerable Versions:
0:4.18.0-553.rt7.342.el8_10, 0:4.18.0-553.el8_10, 0:5.14.0-427.13.1.el9_4

Timeline

Official Publish: October 5th, 2023
Last Modified: November 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)