CVE-2023-35829: Use After Free
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdecremove in drivers/staging/media/rkvdec/rkvdec.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35829?
CVE-2023-35829 is classified as a medium-severity vulnerability due to a use-after-free flaw in the Linux kernel.
How do I fix CVE-2023-35829?
To fix CVE-2023-35829, upgrade to a version of the Linux kernel that is greater than or equal to 6.3.2 or apply the relevant patches.
Which Linux kernel versions are affected by CVE-2023-35829?
CVE-2023-35829 affects Linux kernel versions prior to 6.3.2, including versions 5.8 through 6.3.
What components are impacted by CVE-2023-35829?
CVE-2023-35829 specifically impacts the rkvdec driver within the Linux kernel's media subsystem.
Is CVE-2023-35829 a local or remote exploit?
CVE-2023-35829 can potentially allow local users to exploit the vulnerability, making it a local privilege escalation issue.