CVE-2023-1193Use After Free in Kernel

CWE-416Use After Free6 documents6 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 79.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1
Latest updateNov 14

Description

A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. This issue could allow an attacker to crash the system by accessing freed work.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-1193: A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel2023-11-01
GHSA
GHSA-vv37-54q4-33cj: A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel2023-11-01

📋Vendor Advisories

3
Microsoft
Use-after-free in setup_async_work()2023-11-14
Debian
CVE-2023-1193: linux - A use-after-free flaw was found in setup_async_work in the KSMBD implementation ...2023
Red Hat
kernel: use-after-free in setup_async_work()2022-10-02
CVE-2023-1193 — Use After Free in Linux Kernel | cvebase