CVE-2023-2457
published 2023-05-12CVE-2023-2457: Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.38%
31.0th percentile
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 113.0.5672.114 | 113.0.5672.114 | |
| chrome | >= 113.0.5672.114 < 113.0.5672.114 | 113.0.5672.114 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-76rv-vcjw-7q23: Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113
ghsa_unreviewed·2023-05-12
CVE-2023-2457 [HIGH] CWE-787 GHSA-76rv-vcjw-7q23: Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113
Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)
Red Hat
kernel: drm/amdgpu: drop redundant sched job cleanup when cs is aborted
vendor_redhat·2025-09-15·CVSS 5.5
CVE-2023-53228 [MEDIUM] CWE-476 kernel: drm/amdgpu: drop redundant sched job cleanup when cs is aborted
kernel: drm/amdgpu: drop redundant sched job cleanup when cs is aborted
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: drop redundant sched job cleanup when cs is aborted
Once command submission failed due to userptr invalidation in
amdgpu_cs_submit, legacy code will perform cleanup of scheduler
job. However, it's not needed at all, as former commit has integrated
job cleanup stuff into amdgpu_job_free. Otherwise, because of double
free, a NULL pointer dereference will occur in such scenario.
Bug: https://gitlab.freedesktop.org/drm/amd/-/issues/2457
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red H
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-2457
vendor_chrome·2023-05-09·CVSS 8.8
CVE-2023-2457 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-2457
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2023-2457
No detection rules found.
No public exploits indexed.
2023-05-12
Published