First published: Sun Jun 18 2023(Updated: )
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <6.3.2 | |
Linux Kernel | >=5.8<5.10.180 | |
Linux Kernel | >=5.11<5.15.111 | |
Linux Kernel | >=5.16<6.1.28 | |
Linux Kernel | >=6.2<6.2.15 | |
Linux Kernel | >=6.3<6.3.2 | |
NetApp H300S Firmware | ||
NetApp H410S Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.19-1 6.12.20-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35829 is classified as a medium-severity vulnerability due to a use-after-free flaw in the Linux kernel.
To fix CVE-2023-35829, upgrade to a version of the Linux kernel that is greater than or equal to 6.3.2 or apply the relevant patches.
CVE-2023-35829 affects Linux kernel versions prior to 6.3.2, including versions 5.8 through 6.3.
CVE-2023-35829 specifically impacts the rkvdec driver within the Linux kernel's media subsystem.
CVE-2023-35829 can potentially allow local users to exploit the vulnerability, making it a local privilege escalation issue.