First published: Sun Jun 18 2023(Updated: )
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <6.3.2 | |
Linux Kernel | >=4.19<4.19.283 | |
Linux Kernel | >=4.20<5.4.243 | |
Linux Kernel | >=5.5<5.10.180 | |
Linux Kernel | >=5.11<5.15.111 | |
Linux Kernel | >=5.16<6.1.28 | |
Linux Kernel | >=6.2<6.2.15 | |
Linux Kernel | >=6.3<6.3.2 | |
NetApp H300S Firmware | ||
NetApp H410C Firmware | ||
NetApp H410S Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.19-1 6.12.20-1 |
https://lore.kernel.org/lkml/CAJedcCwkuznS1kSTvJXhzPoavcZDWNhNMshi-Ux0spSVRwU=RA%40mail.gmail.com/T/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-35828 is considered to be high, as it involves a use-after-free vulnerability in the Linux kernel.
You can fix CVE-2023-35828 by upgrading to a patched version of the Linux kernel that is 6.3.2 or higher, or any of the mentioned secure versions like 5.10.223-1 or 6.1.123-1.
CVE-2023-35828 affects Linux kernel versions before 6.3.2, and also specific earlier versions including 4.19 and 5.4.
CVE-2023-35828 is a use-after-free vulnerability within the renesas_usb3 driver in the Linux kernel.
Yes, certain NetApp models such as H300S, H410C, H410S, H500S, and H700S may be affected by CVE-2023-35828 if they utilize vulnerable Linux kernel versions.