CVE-2023-1249 — Use After Free in Kernel
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 83.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateJul 6
Description
A use-after-free flaw was found in the Linux kernel’s core dump subsystem. This flaw allows a local user to crash the system. Only if patch 390031c94211 ("coredump: Use the vma snapshot in fill_files_note") not applied yet, then kernel could be affected.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages10 packages
🔴Vulnerability Details
2📋Vendor Advisories
3Microsoft▶
A use-after-free flaw was found in the Linux kernel’s core dump subsystem. This flaw allows a local user to crash the system. Only if patch 390031c94211 ("coredump: Use the vma snapshot in fill_files_↗2023-03-14
Debian▶
CVE-2023-1249: linux - A use-after-free flaw was found in the Linux kernel’s core dump subsystem. This ...↗2023
Red Hat▶
kernel: missing mmap_lock in file_files_note that could possibly lead to a use after free in the coredump code↗2022-01-31