Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-30772

Опубликовано: 12 мар. 2023
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proximate attacker unplugs a device.

A race condition was found in the Linux kernel's DA9150 charger when removing the module before cleanup in the da9150_charger_remove function. This can result in a use-after-free issue, possibly leading to a system crash or other undefined behaviors.

Отчет

Red Hat Enterprise Linux 6, 7, and 8 are not affected by this flaw as they did not include support for the DA9150 charger (CONFIG_CHARGER_DA9150 is not set).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362->CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2216121kernel: da9150: race condition leading to use-after-free in da9150_charger_remove()

EPSS

Процентиль: 18%
0.00059
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
почти 3 года назад

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proximate attacker unplugs a device.

CVSS3: 6.4
nvd
почти 3 года назад

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proximate attacker unplugs a device.

CVSS3: 6.4
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 6.4
debian
почти 3 года назад

The Linux kernel before 6.2.9 has a race condition and resultant use-a ...

CVSS3: 6.4
github
почти 3 года назад

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proximate attacker unplugs a device.

EPSS

Процентиль: 18%
0.00059
Низкий

6.4 Medium

CVSS3