CVE-2023-2898 — NULL Pointer Dereference in Linux
Severity
4.7MEDIUMNVD
OSV7.8OSV7.1
EPSS
0.0%
top 94.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 26
Latest updateSep 19
Description
There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6
Affected Packages3 packages
Also affects: Debian Linux 10.0, 11.0, 12.0
Patches
🔴Vulnerability Details
12OSV▶
linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-raspi vulnerabilities↗2023-09-11