VYPR
High severity8.8NVD Advisory· Published Sep 29, 2023· Updated Jun 17, 2026

CVE-2023-44466

CVE-2023-44466

Description

An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP packet in ceph_decode_32.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.11,<5.15.121
    • (no CPE)
    • (no CPE)range: <6.4.5

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.