Количество 70
Количество 70
ELSA-2023-13047
ELSA-2023-13047: kernel security update (IMPORTANT)
ELSA-2023-7749
ELSA-2023-7749: kernel security update (IMPORTANT)

CVE-2023-1192
A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service.

CVE-2023-1192
A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service.

CVE-2023-1192
A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service.

CVE-2023-1192
CVE-2023-1192
A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS ...

SUSE-SU-2023:4071-1
Security update for the Linux Kernel

SUSE-SU-2023:4093-1
Security update for the Linux Kernel

SUSE-SU-2023:4072-2
Security update for the Linux Kernel

SUSE-SU-2023:4072-1
Security update for the Linux Kernel
GHSA-r277-j8m2-3x97
A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service.

BDU:2023-01276
Уязвимость функции smb2_is_status_io_timeout() компоненты SMB ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

SUSE-SU-2023:4058-1
Security update for the Linux Kernel

SUSE-SU-2023:4057-1
Security update for the Linux Kernel

ROS-20240812-16
Множественные уязвимости kernel-lt

CVE-2023-5345
A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705.

CVE-2023-5345
A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705.

CVE-2023-5345
A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705.

CVE-2023-5345
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
ELSA-2023-13047 ELSA-2023-13047: kernel security update (IMPORTANT) | больше 1 года назад | |||
ELSA-2023-7749 ELSA-2023-7749: kernel security update (IMPORTANT) | больше 1 года назад | |||
![]() | CVE-2023-1192 A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад |
![]() | CVE-2023-1192 A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service. | CVSS3: 6.5 | 0% Низкий | почти 3 года назад |
![]() | CVE-2023-1192 A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад |
![]() | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2023-1192 A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS ... | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
![]() | SUSE-SU-2023:4071-1 Security update for the Linux Kernel | больше 1 года назад | ||
![]() | SUSE-SU-2023:4093-1 Security update for the Linux Kernel | почти 2 года назад | ||
![]() | SUSE-SU-2023:4072-2 Security update for the Linux Kernel | больше 1 года назад | ||
![]() | SUSE-SU-2023:4072-1 Security update for the Linux Kernel | почти 2 года назад | ||
GHSA-r277-j8m2-3x97 A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
![]() | BDU:2023-01276 Уязвимость функции smb2_is_status_io_timeout() компоненты SMB ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
![]() | SUSE-SU-2023:4058-1 Security update for the Linux Kernel | почти 2 года назад | ||
![]() | SUSE-SU-2023:4057-1 Security update for the Linux Kernel | почти 2 года назад | ||
![]() | ROS-20240812-16 Множественные уязвимости kernel-lt | CVSS3: 9.8 | 12 месяцев назад | |
![]() | CVE-2023-5345 A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705. | CVSS3: 7.8 | 0% Низкий | почти 2 года назад |
![]() | CVE-2023-5345 A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705. | CVSS3: 7.8 | 0% Низкий | почти 2 года назад |
![]() | CVE-2023-5345 A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705. | CVSS3: 7.8 | 0% Низкий | почти 2 года назад |
![]() | CVSS3: 7.8 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу