PT-2023-3674 · Linux+6 · Linux Kernel+6
Xingyuan Mo
·
Publicado
2023-04-12
·
Atualizado
2024-11-21
·
CVE-2023-38409
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.2.12
Description
The issue is related to the use of memory after it has been freed in the set con2fb map() function in the Linux kernel. This can lead to a denial of service. The problem arises because an assignment occurs only for the first vc, causing the fbcon registered fb and fbcon display arrays to become desynchronized in fbcon mode deleted, as the con2fb map points to the old fb info.
Recommendations
For Linux kernel versions prior to 6.2.12, update to version 6.2.12 or later to resolve the issue.
As a temporary workaround, consider restricting access to the set con2fb map() function in the fbcon.c module until a patch is available.
Correção
Race Condition
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Centos
Linux Kernel
Red Hat
Rocky Linux
Suse