Legacy Protocols in Entra ID Exploited to Bypass MFA
May 12, 2025VS Code in Browser Exposes Sessions
May 12, 2025Legacy Protocols in Entra ID Exploited to Bypass MFA
May 12, 2025VS Code in Browser Exposes Sessions
May 12, 2025Severity
Medium
Analysis Summary
CVE-2023-53133 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by an infinite loop error when len is 0 in tcp_bpf_recvmsg_parser().
CVE-2023-53131 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a server shutdown leak in SUNRPC.
Impact
- Denial of Service
Indicators of Compromise
CVE
CVE-2023-53133
CVE-2023-53131
Affected Vendors
Affected Products
- Linux Kernel - 604326b41a6fb9b4a78b6179335decee0365cd8c
- Linux Kernel - 4.20
- Linux Kernel - ed6473ddc704a2005b9900ca08e236ebb2d8540a
- Linux Kernel - 4.12
Remediation
Upgrade to the latest version of the Kernel, available from the Linux Kernel GIT Repository.