{"id":"CVE-2023-0122","details":"A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in nvmet_setup_auth(), allows an attacker to perform a Pre-Auth Denial of Service (DoS) attack on a remote machine. Affected versions v6.0-rc1 to v6.0-rc3, fixed in v6.0-rc4.","modified":"2026-05-04T08:39:27.511164Z","published":"2023-01-17T21:15:14.853Z","withdrawn":"2026-05-04T08:39:27.511164Z","related":["SUSE-SU-2023:0433-1","SUSE-SU-2023:0488-1","SUSE-SU-2023:0774-1","SUSE-SU-2023:1608-1","SUSE-SU-2023:2646-1","SUSE-SU-2023:2809-1","SUSE-SU-2023:2871-1"],"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2023/01/18/1"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230302-0002/"},{"type":"FIX","url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=da0342a3aa0357795224e6283df86444e1117168"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"6.0-rc1"}]},{"events":[{"introduced":"0"},{"last_affected":"6.0-rc2"}]},{"events":[{"introduced":"0"},{"last_affected":"6.0-rc3"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-0122.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}