First published: Mon Jul 10 2023(Updated: )
A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of service condition.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <6.3 | 6.3 |
Linux Linux kernel | <6.3 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux | =9.0 | |
Fedoraproject Fedora |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4133 is a use-after-free vulnerability in the cxgb4 driver in the Linux kernel, which can cause a denial of service condition.
CVE-2023-4133 has a severity rating of medium (5.5).
The affected software includes Red Hat Kernel 6.3, Linux Kernel up to version 6.3, Red Hat Enterprise Linux 8.0, Red Hat Enterprise Linux 9.0, and Fedora.
CVE-2023-4133 can be exploited by a local user to crash the system, leading to a denial of service.
Yes, Red Hat provides a fix for CVE-2023-4133 in their kernel version 6.3 and above.