Bug 2213414 (CVE-2023-3159) - CVE-2023-3159 kernel: use after free issue in driver/firewire in outbound_phy_packet_callback
Summary: CVE-2023-3159 kernel: use after free issue in driver/firewire in outbound_phy...
Keywords:
Status: NEW
Alias: CVE-2023-3159
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2213420 2213421
Blocks: 2213412
TreeView+ depends on / blocked
 
Reported: 2023-06-08 05:54 UTC by Rohit Keshri
Modified: 2023-09-08 20:13 UTC (History)
44 users (show)

Fixed In Version: Kernel 5.18-rc6
Doc Type: ---
Doc Text:
A use-after-free flaw was found in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. This flaw allows a local attacker with special privileges to cause a use-after-free issue when the queue_event() fails.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2023-06-08 05:54:54 UTC
An use after free issue was dicovered in driver/firewire in the Linux Kernel. The use after free in outbound_phy_packet_callback() could be trigerred when queue_event() fails.

Refer:
https://github.com/torvalds/linux/commit/b7c81f80246fac44077166f3e07103affe6db8ff


Note You need to log in before you can comment on or make changes to this bug.