Bug 2182031 (CVE-2023-1652) - CVE-2023-1652 Kernel: use-after-free in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c
Summary: CVE-2023-1652 Kernel: use-after-free in nfsd4_ssc_setup_dul in fs/nfsd/nfs4pr...
Keywords:
Status: NEW
Alias: CVE-2023-1652
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2182039 2182040
Blocks: 2165909
TreeView+ depends on / blocked
 
Reported: 2023-03-27 10:55 UTC by Rohit Keshri
Modified: 2023-11-09 07:10 UTC (History)
44 users (show)

Fixed In Version: Kernel 6.2 RC5
Doc Type: If docs needed, set a value
Doc Text:
A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2023:6835 0 None None None 2023-11-09 07:10:52 UTC
Red Hat Product Errata RHSA-2023:6583 0 None None None 2023-11-07 08:20:18 UTC

Description Rohit Keshri 2023-03-27 10:55:33 UTC
There is a use-after-free bug in nfsd4_ssc_setup_dul() in fs/nfsd/nfs4proc.c in
Linux kernel through v6.2-rc4, which allows an attacker to trigger Denial of
Service.

Reference:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e6cf91b7b47ff82b624bdfe2fdcde32bb52e71dd

Comment 4 errata-xmlrpc 2023-11-07 08:20:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:6583 https://access.redhat.com/errata/RHSA-2023:6583


Note You need to log in before you can comment on or make changes to this bug.