CVE-2023-35826: Race Condition
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrusremove in drivers/staging/media/sunxi/cedrus/cedrus.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35826?
CVE-2023-35826 has been classified as a significant security vulnerability due to the use-after-free issue in the Linux kernel.
How do I fix CVE-2023-35826?
To fix CVE-2023-35826, update your Linux kernel to version 6.3.2 or later.
Which versions of the Linux kernel are affected by CVE-2023-35826?
CVE-2023-35826 affects Linux kernel versions prior to 6.3.2, including versions from 5.18 up to 6.2.15.
Are any NetApp systems vulnerable to CVE-2023-35826?
Yes, certain NetApp systems such as the h300s, h410c, h410s, h500s, and h700s may be vulnerable to CVE-2023-35826.
What kind of issue is described in CVE-2023-35826?
CVE-2023-35826 describes a use-after-free vulnerability that can lead to potential memory corruption in the Linux kernel.