CVE-2023-3439

CVSS v3.1 4.7 (Medium)
47% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 1
Advisories 3

A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object, potentially leading to a denial of service.

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Fedora Project
Published Date
2023-06-28 21:15:10
(14 months ago)
Updated Date
2023-07-06 21:39:33
(14 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 5.18 version cpe:2.3:o:linux:linux_kernel < 5.18
  Linux Kernel 5.18 Rc1 cpe:2.3:o:linux:linux_kernel:5.18:rc1
  Linux Kernel 5.18 Rc2 cpe:2.3:o:linux:linux_kernel:5.18:rc2
  Linux Kernel 5.18 Rc3 cpe:2.3:o:linux:linux_kernel:5.18:rc3
  Linux Kernel 5.18 Rc4 cpe:2.3:o:linux:linux_kernel:5.18:rc4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...