First published: Wed Jun 07 2023(Updated: )
A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in Linux Kernel. This flaw could allow a local attacker to crash the system at device disconnect. This vulnerability could even lead to a kernel information leak problem. Refer: <a href="https://lore.kernel.org/lkml/CAPDyKFoV9aZObZ5GBm0U_-UVeVkBN_rAG-kH3BKoP4EXdYM4bw@mail.gmail.com/t/">https://lore.kernel.org/lkml/CAPDyKFoV9aZObZ5GBm0U_-UVeVkBN_rAG-kH3BKoP4EXdYM4bw@mail.gmail.com/t/</a>
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Kernel | <6.4 | 6.4 |
Linux Kernel | >=2.6.39<4.14.316 | |
Linux Kernel | >=4.15<4.19.284 | |
Linux Kernel | >=4.20<5.4.244 | |
Linux Kernel | >=5.5<5.10.181 | |
Linux Kernel | >=5.11<5.15.113 | |
Linux Kernel | >=5.16<6.1.30 | |
Linux Kernel | >=6.2<6.3.4 | |
netapp hci baseboard management controller | =h300s | |
netapp hci baseboard management controller | =h410c | |
netapp hci baseboard management controller | =h410s | |
netapp hci baseboard management controller | =h500s | |
netapp hci baseboard management controller | =h700s | |
Debian GNU/Linux | =10.0 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.15-1 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3141 is considered to be of high severity due to its potential to allow local attackers to crash the system and cause a kernel information leak.
To remediate CVE-2023-3141, update to the kernel version 6.4 or later where this vulnerability is addressed.
CVE-2023-3141 affects various versions of the Linux Kernel, and specific software components from IBM and NetApp.
CVE-2023-3141 is deemed a local vulnerability, requiring an attacker to have local access to the affected system to exploit it.
Symptoms of an exploit of CVE-2023-3141 may include system crashes or unexpected behavior when disconnecting devices.