Back to bug 2215841

Who When What Removed Added
TEJ RATHI 2023-06-19 07:06:58 UTC CC acaringi, allarkin, bhu, chwhite, dbohanno, ddepaula, debarbos, dfreiber, dvlasenk, ezulian, hkrzesin, jarod, jburrell, jdenham, jfaracco, jferlan, jforbes, jlelli, joe.lawrence, jshortt, jstancek, jwyatt, kcarcia, kernel-mgr, ldoskova, lgoncalv, lleshchi, lzampier, nmurray, ptalbert, qzhao, rogbas, rrobaina, rvrbovsk, rysulliv, scweaver, swood, tyberry, vkumar, walters, wcosta, williams, wmealing, ycote, ymankad
TEJ RATHI 2023-06-19 07:38:45 UTC Blocks 2215849
Product Security DevOps Team 2023-06-19 21:26:55 UTC Status NEW CLOSED
Resolution --- NOTABUG
Last Closed 2023-06-19 21:26:55 UTC
Mauro Matteo Cascella 2023-06-20 08:45:16 UTC Depends On 2186164
Mauro Matteo Cascella 2023-06-20 08:46:17 UTC Depends On 2186164
Alias TRIAGE-CVE-2023-35829 CVE-2023-35829
Mauro Matteo Cascella 2023-06-20 08:46:48 UTC Summary TRIAGE-CVE-2023-35829 kernel: use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c CVE-2023-35829 kernel: use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c
Mauro Matteo Cascella 2023-06-20 08:47:11 UTC Depends On 2186164
Mauro Matteo Cascella 2023-06-20 09:02:56 UTC Summary CVE-2023-35829 kernel: use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c CVE-2023-35829 kernel: rkvdec: race condition leading to use-after-free in rkvdec_remove()
Mauro Matteo Cascella 2023-06-20 09:29:49 UTC Fixed In Version kernel 6.4-rc1
Mauro Matteo Cascella 2023-06-20 11:00:56 UTC Doc Text A race condition vulnerability was found in the Linux kernel's rkvdec driver when removing the module before cleanup in the rkvdec_remove function. This flaw can eventually result in a use-after-free issue, possibly leading to a system crash or other undefined behaviors.
Paige Jung 2023-06-20 14:14:29 UTC Doc Text A race condition vulnerability was found in the Linux kernel's rkvdec driver when removing the module before cleanup in the rkvdec_remove function. This flaw can eventually result in a use-after-free issue, possibly leading to a system crash or other undefined behaviors. A race condition was found in the Linux kernel's rkvdec driver when removing the module before cleanup in the rkvdec_remove function. This can result in a use-after-free issue, possibly leading to a system crash or other undefined behaviors.

Back to bug 2215841