A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in nvmetsetupauth(), allows an attacker to perform a Pre-Auth Denial of Service (DoS) attack on a remote machine. Affected versions v6.0-rc1 to v6.0-rc3, fixed in v6.0-rc4.
[
{
"id": "CVE-2023-0122-119c8939",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@da0342a3aa0357795224e6283df86444e1117168",
"target": {
"function": "nvmet_setup_auth",
"file": "drivers/nvme/target/auth.c"
},
"digest": {
"length": 2308.0,
"function_hash": "65471675084753984992745238070084746237"
},
"signature_type": "Function"
},
{
"id": "CVE-2023-0122-8c2be4dd",
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@da0342a3aa0357795224e6283df86444e1117168",
"target": {
"file": "drivers/nvme/target/auth.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"114985021551554062589883220698412911718",
"245172868583420663926983633547187561283",
"271864147143176182694820917691843249391",
"219828271561680188083360920946018315796"
]
},
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-0122.json"