CVE-2023-1855

CVSS v3.1 6.3 (Medium)
63% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 2
Advisories 33

A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). This flaw could allow a local attacker to crash the system due to a race problem. This vulnerability could even lead to a kernel information leak problem.

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2023-04-05 20:15:07
(17 months ago)
Updated Date
2023-11-07 04:05:10
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 6.3 version cpe:2.3:o:linux:linux_kernel < 6.3
  Linux Kernel from 4.9 version and prior 4.14.311 version cpe:2.3:o:linux:linux_kernel >= 4.9 < 4.14.311
  Linux Kernel from 4.15 version and prior 4.19.279 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.19.279
  Linux Kernel from 4.20 version and prior 5.4.238 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 5.4.238
  Linux Kernel from 5.5 version and prior 5.10.176 version cpe:2.3:o:linux:linux_kernel >= 5.5 < 5.10.176
  Linux Kernel from 5.11 version and prior 5.15.104 version cpe:2.3:o:linux:linux_kernel >= 5.11 < 5.15.104
  Linux Kernel from 5.16 version and prior 6.1.21 version cpe:2.3:o:linux:linux_kernel >= 5.16 < 6.1.21
  Linux Kernel from 6.2 version and prior 6.2.8 version cpe:2.3:o:linux:linux_kernel >= 6.2 < 6.2.8
  Linux Kernel 6.3 Rc1 cpe:2.3:o:linux:linux_kernel:6.3:rc1
  Linux Kernel 6.3 Rc2 cpe:2.3:o:linux:linux_kernel:6.3:rc2
  Linux Kernel 6.3 Rc3 cpe:2.3:o:linux:linux_kernel:6.3:rc3

Configuration #2

    CPE23 From Up To
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...