Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35826

Опубликовано: 19 июн. 2023
Источник: redhat
CVSS3: 6.4

Описание

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.

A race condition was found in the Linux kernel's Allwinner Cedrus VPU driver when removing the module before cleanup in the cedrus_remove function. This can result in a use-after-free issue, possibly leading to a system crash or other undefined behaviors.

Отчет

No Red Hat products are affected by this flaw, as the sunxi-cedrus driver is not included in any shipping kernel release.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362->CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2215838kernel: cedrus: race condition leading to use-after-free in cedrus_remove()

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
около 2 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.

CVSS3: 7
nvd
около 2 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.

CVSS3: 7
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 7
debian
около 2 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after- ...

CVSS3: 7
github
около 2 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.

6.4 Medium

CVSS3

Уязвимость CVE-2023-35826