CVE-2023-26589

CWE-416Use After Free6 documents4 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 82.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateApr 24

Description

Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages2 packages

🔴Vulnerability Details

5
OSV
linux-azure-6.5 vulnerabilities2024-04-24
OSV
linux-lowlatency-hwe-6.5 vulnerabilities2024-04-22
OSV
linux, linux-aws, linux-aws-6.5, linux-azure, linux-gcp, linux-gcp-6.5, linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-nvidia-6.5, linux-oem-6.5, linux-oracle, linux-oracle-6.5, linux-raspi, lin2024-04-19
GHSA
GHSA-wfc8-v3hg-jvrw: Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via2023-11-14
CVEList
CVE-2023-26589: Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via2023-11-14
CVE-2023-26589 (MEDIUM CVSS 5.5) | Use after free in some Intel(R) Apt | cvebase.io