CVE-2023-35828: Race Condition
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesasusb3remove in drivers/usb/gadget/udc/renesasusb3.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch Linux kernel before 6.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35828?
The severity of CVE-2023-35828 is considered to be high, as it involves a use-after-free vulnerability in the Linux kernel.
How do I fix CVE-2023-35828?
You can fix CVE-2023-35828 by upgrading to a patched version of the Linux kernel that is 6.3.2 or higher, or any of the mentioned secure versions like 5.10.223-1 or 6.1.123-1.
Which versions of the Linux kernel are affected by CVE-2023-35828?
CVE-2023-35828 affects Linux kernel versions before 6.3.2, and also specific earlier versions including 4.19 and 5.4.
What kind of vulnerability is CVE-2023-35828?
CVE-2023-35828 is a use-after-free vulnerability within the renesas_usb3 driver in the Linux kernel.
Is my NetApp device affected by CVE-2023-35828?
Yes, certain NetApp models such as H300S, H410C, H410S, H500S, and H700S may be affected by CVE-2023-35828 if they utilize vulnerable Linux kernel versions.