CVE-2023-45871 is an Important-rated buffer overflow in the Linux kernel’s Intel IGB Ethernet driver. When rx-all/store-bad-packet behavior is enabled, an oversized physical-layer frame can overflow a receive-ring buffer in igb_configure_rx_ring, potentially compromising system confidentiality, integrity, and availability. Red Hat assigned the flaw a CVSS v3.1 score of 7.5; exploitation requires an adjacent-network attacker and is considered high complexity because it depends on oversized frames and a non-default configuration.
The upstream kernel fix updates igb_set_rx_buffer_len to allocate large receive buffers on systems with page sizes below 8192 bytes when either frames exceed IGB_MAX_FRAME_BUILD_SKB or the E1000_RCTL_SBP receive-control flag is set. Red Hat released corrected kernel, kernel-rt, and kpatch packages for affected Red Hat Enterprise Linux 7 and 8 streams in February and March 2024, with no qualifying mitigation listed at the time of its advisory.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:1332 to fix CVE-2023-45871 in the Red Hat Enterprise Linux 7 kernel-rt stream.
Red Hat released RHSA-2024:1323 to fix CVE-2023-45871 in the Red Hat Enterprise Linux 7 kpatch-patch stream.
Red Hat released RHSA-2024:1249 for the RHEL 7 kernel and RHSA-2024:1268 and RHSA-2024:1269 for the RHEL 8.2 Advanced Update Support kernel and 8.2 Telecommunications Update Service kernel-rt, addressing CVE-2023-45871.
Red Hat released RHSA-2024:0999 to fix CVE-2023-45871 in the Red Hat Enterprise Linux 7.7 Advanced Update Support kernel.
Red Hat released RHSA-2024:0980 to fix CVE-2023-45871 in the Red Hat Enterprise Linux 7.6 Advanced Update Support kernel.
Red Hat released fixes for CVE-2023-45871 in Red Hat Enterprise Linux 8 kernel, kernel-rt, and kpatch-patch streams through RHSA-2024:0897, RHSA-2024:0881, and RHSA-2024:0876.
The Linux stable tree updated the Intel igb driver so systems with page sizes below 8192 bytes select large receive buffers when the E1000_RCTL_SBP flag is enabled, in addition to oversized maximum-frame configurations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.