CVE-2023-2513Use After Free in Kernel

CWE-416Use After Free11 documents10 sources
Severity
6.7MEDIUMNVD
OSV4.7
EPSS
0.0%
top 97.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8
Latest updateFeb 14

Description

A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages4 packages

Debianlinux/linux_kernel< 5.10.140-1+3
Ubuntulinux/linux_kernel< 4.4.0-243.277
Palo Altopaloalto/pan-os

Also affects: Enterprise Linux 6.0, 7.0, 8.0, 9.0

Patches

🔴Vulnerability Details

4
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2023-07-26
GHSA
GHSA-8m42-pwwf-cc8j: A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes2023-05-08
CVEList
CVE-2023-2513: A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes2023-05-08
OSV
CVE-2023-2513: A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes2023-05-08

📋Vendor Advisories

5
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Ubuntu
Linux kernel vulnerabilities2023-07-26
Microsoft
A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to caus2023-05-09
Debian
CVE-2023-2513: linux - A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem i...2023
Red Hat
kernel: ext4: use-after-free in ext4_xattr_set_entry()2022-06-14

💬Community

1
Bugzilla
CVE-2023-2513 kernel: ext4: use-after-free in ext4_xattr_set_entry()2023-05-04
CVE-2023-2513 — Use After Free in Linux Kernel | cvebase