Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35828

Опубликовано: 19 июн. 2023
Источник: redhat
CVSS3: 6.4

Описание

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

A race condition was found in the Linux kernel's Renesas USB3.0 controller when removing the module before cleanup in the usbhs_remove function. This can result in a use-after-free issue, possibly leading to a system crash or other undefined behaviors.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362->CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2215839kernel: renesas_usb3: race condition leading to use-after-free in renesas_usb3_remove()

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
около 2 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

CVSS3: 7
nvd
около 2 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

CVSS3: 7
debian
около 2 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after- ...

CVSS3: 7
github
около 2 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

CVSS3: 7
fstec
около 2 лет назад

Уязвимость функции renesas_usb3_remove() в модуле drivers/usb/gadget/udc/renesas_usb3.c драйвера USB устройств Renesas ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации.

6.4 Medium

CVSS3