cbcvebase.
CVE-2023-1838
published 2023-04-05

CVE-2023-1838: A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.25%
16.6th percentile
A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash the system, and could even lead to a kernel information leak problem.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.11-1 (bookworm)linux 5.17.11-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.120-15.10.120-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 4.15.0-224.2364.15.0-224.236
linuxlinux_kernel>= 4.13 < 4.14.3174.14.317
linuxlinux_kernel>= 4.15 < 4.19.2454.19.245
linuxlinux_kernel>= 4.20 < 5.4.1965.4.196
linuxlinux_kernel>= 5.11 < 5.15.425.15.42
linuxlinux_kernel>= 5.16 < 5.17.105.17.10
linuxlinux_kernel>= 5.5 < 5.10.1185.10.118
msrccbl2_kernel_5.15.107.1-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_kernel_5.10.177.1-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.