Bug 2187773 (CVE-2023-2162) - CVE-2023-2162 Kernel: UAF during login when accessing the shost ipaddress
Summary: CVE-2023-2162 Kernel: UAF during login when accessing the shost ipaddress
Keywords:
Status: NEW
Alias: CVE-2023-2162
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2187784 2187785 2187786 2187788
Blocks: 2186426
TreeView+ depends on / blocked
 
Reported: 2023-04-18 16:24 UTC by Rohit Keshri
Modified: 2023-07-07 08:30 UTC (History)
44 users (show)

Fixed In Version: Kernel 6.2 RC6
Doc Type: If docs needed, set a value
Doc Text:
A use-after-free flaw was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in the SCSI sub-component in the Linux Kernel. This issue could allow an attacker to leak kernel internal information.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2023-04-18 16:24:38 UTC
A use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux Kernel. In this flaw an attacker could leak kernel internal information.

Reference:
https://www.spinics.net/lists/linux-scsi/msg181542.html


Note You need to log in before you can comment on or make changes to this bug.