CVE-2023-3863: Use-after-free in nfc_llcp_find_loca in net/nfc/llcp_core.c
A use-after-free flaw was found in nfcllcpfindlocal in net/nfc/llcpcore.c in NFC in the Linux Kernel. In this flaw a local user with special privilege may impact kernel information leak problem.
crash stack: BUG: KASAN: slab-use-after-free in nfcgenlllcgetparams+0x72f/0x780 net/nfc/netlink.c:1045 Read of size 8 at addr ffff888105b0e410 by task 20114
Call Trace: <TASK> dumpstack lib/dumpstack.c:88 [inline] dumpstacklvl+0x72/0xa0 lib/dumpstack.c:106 printaddressdescription mm/kasan/report.c:319 [inline] printreport+0xcc/0x620 mm/kasan/report.c:430 kasanreport+0xb2/0xe0 mm/kasan/report.c:536 nfcgenlsendparams net/nfc/netlink.c:999 [inline] nfcgenlllcgetparams+0x72f/0x780 net/nfc/netlink.c:1045 genlfamilyrcvmsgdoit.isra.0+0x1ee/0x2e0 net/netlink/genetlink.c:968 genlfamilyrcvmsg net/netlink/genetlink.c:1048 [inline] genlrcvmsg+0x503/0x7d0 net/netlink/genetlink.c:1065 netlinkrcvskb+0x161/0x430 net/netlink/afnetlink.c:2548 genlrcv+0x28/0x40 net/netlink/genetlink.c:1076 netlinkunicastkernel net/netlink/afnetlink.c:1339 [inline] netlinkunicast+0x644/0x900 net/netlink/afnetlink.c:1365 netlinksendmsg+0x934/0xe70 net/netlink/afnetlink.c:1913 socksendmsgnosec net/socket.c:724 [inline] socksendmsg+0x1b6/0x200 net/socket.c:747 syssendmsg+0x6e9/0x890 net/socket.c:2501 syssendmsg+0x110/0x1b0 net/socket.c:2555 syssendmsg+0xf7/0x1d0 net/socket.c:2584 dosyscallx64 arch/x86/entry/common.c:50 [inline] dosyscall64+0x3f/0x90 arch/x86/entry/common.c:80 entrySYSCALL64afterhwframe+0x72/0xdc
Reference: https://github.com/torvalds/linux/commit/6709d4b7bc2e079241fdef15d1160581c5261c10
Other sources
A use-after-free flaw was found in nfcllcpfindlocal in net/nfc/llcpcore.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3863?
CVE-2023-3863 is classified as a use-after-free vulnerability, which can lead to kernel information leaks.
How do I fix CVE-2023-3863?
To fix CVE-2023-3863, upgrade your Linux Kernel to version 6.5 or apply the relevant patches provided for earlier versions.
Who is affected by CVE-2023-3863?
CVE-2023-3863 affects local users with special privileges on systems running vulnerable versions of the Linux Kernel and Debian Linux distributions.
What can happen if CVE-2023-3863 is exploited?
If exploited, CVE-2023-3863 may allow attackers to leak sensitive kernel information, leading to potential system compromise.
Which systems are vulnerable to CVE-2023-3863?
Affected systems include various versions of the Linux Kernel prior to 6.5 and specific Debian Linux versions 10.0, 11.0, and 12.0.