CVE-2023-26545Double Free in Kernel

CWE-415Double Free43 documents11 sources
Severity
4.7MEDIUMNVD
OSV8.8OSV7.8OSV7.0OSV5.9OSV5.5OSV4.6
EPSS
0.0%
top 97.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateFeb 13

Description

In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages12 packages

NVDlinux/linux_kernel4.16.1.13
Debianlinux/linux_kernel< 5.10.178-1+3
Ubuntulinux/linux_kernel< 4.15.0-209.220+3
debiandebian/linux< linux 6.1.15-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

18
OSV
linux-iot vulnerabilities2023-07-27
OSV
linux-xilinx-zynqmp vulnerabilities2023-07-12
OSV
linux-intel-iotg-5.15 vulnerabilities2023-06-01
OSV
linux-bluefield vulnerabilities2023-05-22
OSV
linux-oem-5.17 vulnerabilities2023-05-10

📋Vendor Advisories

22
CISA ICS
Siemens SCALANCE W7002025-02-13
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Ubuntu
Linux kernel (IoT) vulnerabilities2023-07-27
Ubuntu
Linux kernel (Xilinx ZynqMP) vulnerabilities2023-07-12
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2023-06-01

📄Research Papers

1
arXiv
Top of the Heap: Efficient Memory Error Protection of Safe Heap Objects2024-08-19

💬Community

1
Bugzilla
CVE-2023-26545 kernel: mpls: double free on sysctl allocation failure2023-03-28