PT-2023-4425 · Linux+9 · Linux Kernel+9

Hui Peng

+2

·

Publicado

2023-06-29

·

Atualizado

2024-08-26

·

CVE-2023-40283

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.4.10
Description The issue is related to the l2cap sock release function in the Linux kernel, specifically in the net/bluetooth/l2cap sock.c file. It involves a use-after-free error because the children of an sk are mishandled. This could potentially allow an attacker to cause a denial of service or have other impacts.
Recommendations For Linux kernel versions prior to 6.4.10, update to version 6.4.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the l2cap sock release function in net/bluetooth/l2cap sock.c until a patch is available.

Correção

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2024:0897
ALT-PU-2023-5182
ALT-PU-2023-7439
ALT-PU-2023-8474
ALT-PU-2024-6818
AZL-27936
BDU:2023-04770
CESA-2024_0881
CESA-2024_0897
CVE-2023-40283
DLA-3623-1
DLA-3710-1
DSA-5480-1
DSA-5492-1
LSN-0098-1
LSN-0099-1
OESA-2023-1584
OESA-2023-1585
OESA-2023-1586
OESA-2023-1587
OESA-2023-1588
OPENSUSE-SU-2023_3599-1
OPENSUSE-SU-2023_3599-2
OPENSUSE-SU-2023_3656-1
OPENSUSE-SU-2023_3704-1
OPENSUSE-SU-2023_3704-2
OPENSUSE-SU-2023_3971-1
OPENSUSE-SU-2023_3988-1
OPENSUSE-SU-2023_4058-1
OPENSUSE-SU-2023_4347-1
RHSA-2024:0439
RHSA-2024:0448
RHSA-2024:0461
RHSA-2024:0724
RHSA-2024:0881
RHSA-2024:0897
RHSA-2024:1250
RHSA-2024:1268
RHSA-2024:1269
RHSA-2024:1306
RHSA-2024:1404
RHSA-2024:2582
RHSA-2024:2585
RHSA-2024_0461
RHSA-2024_0881
RHSA-2024_0897
SUSE-SU-2023:3599-1
SUSE-SU-2023:3599-2
SUSE-SU-2023:3601-1
SUSE-SU-2023:3656-1
SUSE-SU-2023:3681-1
SUSE-SU-2023:3705-1
SUSE-SU-2023:3971-1
SUSE-SU-2023:3988-1
SUSE-SU-2023:4030-1
SUSE-SU-2023:4058-1
SUSE-SU-2023:4095-1
SUSE-SU-2023:4142-1
SUSE-SU-2023:4347-1
USN-6343-1
USN-6383-1
USN-6385-1
USN-6386-1
USN-6386-2
USN-6386-3
USN-6387-1
USN-6387-2
USN-6388-1
USN-6396-1
USN-6396-2
USN-6396-3
USN-6466-1

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu