Red Hat addressed CVE-2023-1206, a moderate-severity Linux kernel flaw that lets an attacker create hash collisions in the IPv6 connection lookup table using a modified IPv6 SYN-flood technique. A network-adjacent low-privileged attacker—or an attacker with sufficient bandwidth—can sharply increase connection-lookup costs and drive CPU utilization on servers accepting IPv6 connections to roughly 95%, causing denial of service. Red Hat rates the issue CVSS 5.7; it affects availability but not confidentiality or integrity.
Fixes were released for supported RHEL 8 and RHEL 9 kernel variants, relevant Extended Update Support releases, and Red Hat Virtualization 4 on RHEL 8. RHSA-2023:5603 updates RHEL 9.0 EUS for SAP Solutions kernel-rt to 5.14.0-70.75.1.rt21.146.el9_0; affected systems require a reboot after installation. RHEL 6 and RHEL 7 kernel packages are outside support scope and should be treated as affected.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:6583 to remediate CVE-2023-1206 in the RHEL 9 kernel.
Red Hat released RHSA-2023:5603 and RHSA-2023:5604 for RHEL 9.0 Extended Update Support, and RHSA-2023:5627 for RHEL 8.6 Extended Update Support and Red Hat Virtualization 4 on RHEL 8. RHSA-2023:5603 updated the RHEL 9.0 EUS kernel-rt package to version 5.14.0-70.75.1.rt21.146.el9_0 and also addressed seven other kernel vulnerabilities.
Red Hat released RHSA-2023:6901 for RHEL 8 kernel-rt and RHSA-2023:7077 for the RHEL 8 kernel, addressing CVE-2023-1206.
Fedora remediated the IPv6 connection-lookup hash-collision vulnerability through its 6.4.8 stable kernel updates.
A fix for CVE-2023-1206 was merged into Linux net.git as commit d11b0df7ddf1831f3e170972f43186dad520bfcc and was expected in Linux 6.5-rc4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.