Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-33288

Опубликовано: 10 мар. 2023
Источник: redhat
CVSS3: 6.4

Описание

An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.

A use-after-free flaw was found in bq24190_remove in drivers/power/supply/bq24190_charger.c in the power subsystem in the Linux Kernel. This flaw allows a local attacker to crash the system due to a race problem.

Меры по смягчению последствий

In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel module bq24190-charger. For instructions relating to how to blacklist a kernel module, refer to: https://access.redhat.com/solutions/41278

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2209244kernel: use-after-free in bq24190_remove in drivers/power/supply/bq24190_charger.c

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 2 лет назад

An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.

CVSS3: 4.7
nvd
около 2 лет назад

An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.

CVSS3: 4.7
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 4.7
debian
около 2 лет назад

An issue was discovered in the Linux kernel before 6.2.9. A use-after- ...

CVSS3: 4.7
github
около 2 лет назад

An issue was discovered in the Linux kernel before 6.2.9. A use-after-free flaw was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race problem.

6.4 Medium

CVSS3

Уязвимость CVE-2023-33288