CVE-2023-26545 — Double Free in Kernel
Severity
4.7MEDIUMNVD
OSV8.8OSV7.8OSV7.0OSV5.9OSV5.5OSV4.6
EPSS
0.0%
top 97.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 25
Latest updateFeb 13
Description
In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6
Affected Packages12 packages
Also affects: Debian Linux 10.0