cbqclassify in net/sched/schcbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TCACTSHOT condition rather than valid classification results).
[
{
"deprecated": false,
"target": {
"file": "net/sched/sch_cbq.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@caa4b35b4317d5147b3ab0fbdc9c075c7d2e9c12",
"digest": {
"line_hashes": [
"163845383729980699995478977241030807110",
"106858656585361449288054241501182561840",
"118416195743702263772768219521713563099",
"59791348225991241432262486844038620439",
"221296479765481627423029394361010479491",
"53935334097908504796642566928045868155",
"154780439824615131231732501702994364177",
"286014129021976712049856765522147581204",
"340247920893007341662232118037408106123"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2023-23454-7ac2520c"
},
{
"deprecated": false,
"target": {
"function": "cbq_classify",
"file": "net/sched/sch_cbq.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@caa4b35b4317d5147b3ab0fbdc9c075c7d2e9c12",
"digest": {
"function_hash": "267118344471877037717789205860349371857",
"length": 1397.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2023-23454-bf528797"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-23454.json"