First published: Tue Jun 27 2023(Updated: )
A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object, potentially leading to a denial of service.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | <5.18 | |
Linux Linux kernel | =5.18-rc1 | |
Linux Linux kernel | =5.18-rc2 | |
Linux Linux kernel | =5.18-rc3 | |
Linux Linux kernel | =5.18-rc4 | |
redhat/kernel | <5.18 | 5.18 |
debian/linux | 5.10.223-1 5.10.226-1 6.1.115-1 6.1.119-1 6.11.10-1 6.12.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.