Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-23039

Опубликовано: 22 фев. 2023
Источник: redhat
CVSS3: 6.4

Описание

An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().

A race condition leading to a use-after-free vulnerability was found in the Linux kernel's Sun Virtual Console Concentrator (VCC). This issue can result in a system crash or potential code execution if a physically proximate attacker removes a VCC device while calling open().

Отчет

Red Hat Enterprise Linux is not affected by this flaw, as the Sun Virtual Console Concentrator (CONFIG_VCC) is not enabled in any current shipping kernels.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2174866kernel: tty: vcc: race condition leading to use-after-free in vcc_open()

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
ubuntu
почти 3 года назад

An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().

CVSS3: 5.7
nvd
почти 3 года назад

An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().

CVSS3: 5.7
msrc
почти 3 года назад

An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open() aka a race condition between vcc_open() and vcc_remove().

CVSS3: 5.7
debian
почти 3 года назад

An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers ...

CVSS3: 5.7
github
почти 3 года назад

An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().

6.4 Medium

CVSS3