cbcvebase.
CVE-2023-1855
published 2023-04-05

CVE-2023-1855: A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). This flaw…

PriorityP429medium6.3CVSS 3.1
AVLACHPRLUINSUCHINAH
EPSS
0.24%
14.8th percentile
A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). This flaw could allow a local attacker to crash the system due to a race problem. This vulnerability could even lead to a kernel information leak problem.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.20-2 (bookworm)linux 6.1.20-2 (bookworm)
linuxlinux_kernel< 6.36.3
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-26.1.20-2
linuxlinux_kernel>= 0 < 6.1.20-26.1.20-2
linuxlinux_kernel>= 0 < 6.1.20-26.1.20-2
linuxlinux_kernel>= 0 < 5.4.0-156.1735.4.0-156.173
linuxlinux_kernel>= 0 < 5.15.0-79.865.15.0-79.86
linuxlinux_kernel>= 4.15 < 4.19.2794.19.279
linuxlinux_kernel>= 4.20 < 5.4.2385.4.238
linuxlinux_kernel>= 4.9 < 4.14.3114.14.311
linuxlinux_kernel>= 5.11 < 5.15.1045.15.104
linuxlinux_kernel>= 5.16 < 6.1.216.1.21
linuxlinux_kernel>= 5.5 < 5.10.1765.10.176
linuxlinux_kernel>= 6.2 < 6.2.86.2.8
msrccbl2_hyperv-daemons_5.15.107.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.107.1-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_hyperv-daemons_5.10.177.1-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian6.3MEDIUM
vendor_msrc6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.