First published: Tue May 21 2024(Updated: )
In the Linux kernel, the following vulnerability has been resolved: media: bttv: fix use after free error due to btv-&gt;timeout timer The Linux kernel CVE team has assigned <a href="https://access.redhat.com/security/cve/CVE-2023-52847">CVE-2023-52847</a> to this issue. Upstream advisory: <a href="https://lore.kernel.org/linux-cve-announce/2024052113-CVE-2023-52847-a551@gregkh/T">https://lore.kernel.org/linux-cve-announce/2024052113-CVE-2023-52847-a551@gregkh/T</a>
Credit: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <4.19.299 | 4.19.299 |
redhat/kernel | <5.4.261 | 5.4.261 |
redhat/kernel | <5.10.201 | 5.10.201 |
redhat/kernel | <5.15.139 | 5.15.139 |
redhat/kernel | <6.1.63 | 6.1.63 |
redhat/kernel | <6.5.12 | 6.5.12 |
redhat/kernel | <6.6.2 | 6.6.2 |
redhat/kernel | <6.7 | 6.7 |
Linux Kernel | >=4.15<4.19.299 | |
Linux Kernel | >=4.20<5.4.261 | |
Linux Kernel | >=5.5<5.10.201 | |
Linux Kernel | >=5.11<5.15.139 | |
Linux Kernel | >=5.16<6.1.63 | |
Linux Kernel | >=6.2<6.5.12 | |
Linux Kernel | >=6.6<6.6.2 | |
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Software Stack | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager Virtual Appliance | <=ISVG 10.0.2 | |
IBM Security Verify Governance Identity Manager Container | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52847 is classified as a medium severity vulnerability in the Linux kernel.
To fix CVE-2023-52847, update your Linux kernel to a version greater than or equal to the specified remedies for your distribution.
CVE-2023-52847 affects multiple versions of the Linux kernel including those lower than 4.19.299, 5.4.261, 5.10.201, 5.15.139, 6.1.63, 6.5.12, 6.6.2, and 6.7.
Users and administrators running vulnerable versions of the Linux kernel may be impacted by CVE-2023-52847.
CVE-2023-52847 can potentially allow an attacker to exploit the use after free vulnerability for unauthorized access or control over affected systems.