CVE-2023-3159
published 2023-06-12CVE-2023-3159: A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special…
PriorityP429medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.21%
12.0th percentile
A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.11-1 (bookworm) | linux 5.17.11-1 (bookworm) |
| linux | linux_kernel | < 5.18 | 5.18 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.120-1 | 5.10.120-1 |
| linux | linux_kernel | >= 0 < 5.17.11-1 | 5.17.11-1 |
| linux | linux_kernel | >= 0 < 5.17.11-1 | 5.17.11-1 |
| linux | linux_kernel | >= 0 < 5.17.11-1 | 5.17.11-1 |
| linux | linux_kernel | >= 0 < 3.13.0-193.244 | 3.13.0-193.244 |
| linux | linux_kernel | >= 0 < 4.4.0-243.277 | 4.4.0-243.277 |
| msrc | cbl2_kernel_5.15.116.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_kernel_5.10.183.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-09-06·CVSS 5.3
CVE-2023-3567 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jordy Zomer and Alexandra Sandulescu discovered that syscalls invoking the
do_prlimit() function in the Linux kernel did not properly handle
speculative execution barriers. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2023-0458)
It was discovered that a use-after-free vulnerability existed in the IEEE
1394 (Firewire) implementation in the Linux kernel. A privileged attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2023-3159)
It was discovered that the virtual terminal driver in the Linux kernel
contained a use-after-free vulnerability. A local attacker could use this
to cause a denial of
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-07-26·CVSS 5.3
CVE-2023-2513 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jordy Zomer and Alexandra Sandulescu discovered that syscalls invoking the
do_prlimit() function in the Linux kernel did not properly handle
speculative execution barriers. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2023-0458)
It was discovered that a race condition existed in the btrfs file system
implementation in the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2023-1611)
It was discovered that the XFS file system implementation in the Linux
kernel did not properly perform metadata validation when mounting ce
Microsoft
A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem wh
vendor_msrc·2023-06-13·CVSS 6.7
CVE-2023-3159 [MEDIUM] CWE-416 A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem wh
A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identif
Debian
CVE-2023-3159: linux - A use after free issue was discovered in driver/firewire in outbound_phy_packet_...
vendor_debian·2023·CVSS 6.7
CVE-2023-3159 [MEDIUM] CVE-2023-3159: linux - A use after free issue was discovered in driver/firewire in outbound_phy_packet_...
A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.
Scope: local
bookworm: resolved (fixed in 5.17.11-1)
bullseye: resolved (fixed in 5.10.120-1)
forky: resolved (fixed in 5.17.11-1)
sid: resolved (fixed in 5.17.11-1)
trixie: resolved (fixed in 5.17.11-1)
Red Hat
kernel: use after free issue in driver/firewire in outbound_phy_packet_callback
vendor_redhat·2022-04-09·CVSS 6.7
CVE-2023-3159 [MEDIUM] CWE-416 kernel: use after free issue in driver/firewire in outbound_phy_packet_callback
kernel: use after free issue in driver/firewire in outbound_phy_packet_callback
A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.
A use-after-free flaw was found in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. This flaw allows a local attacker with special privileges to cause a use-after-free issue when the queue_event() fails.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: kernel (Red Ha
OSV
linux vulnerabilities
osv·2023-09-06·CVSS 4.7
CVE-2023-0458 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Jordy Zomer and Alexandra Sandulescu discovered that syscalls invoking the
do_prlimit() function in the Linux kernel did not properly handle
speculative execution barriers. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2023-0458)
It was discovered that a use-after-free vulnerability existed in the IEEE
1394 (Firewire) implementation in the Linux kernel. A privileged attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2023-3159)
It was discovered that the virtual terminal driver in the Linux kernel
contained a use-after-free vulnerability. A local attacker could use this
to cause a denial of service (system crash) or possibly expose sensitive
information (kernel memory).
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2023-07-26·CVSS 4.7
CVE-2023-0458 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Jordy Zomer and Alexandra Sandulescu discovered that syscalls invoking the
do_prlimit() function in the Linux kernel did not properly handle
speculative execution barriers. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2023-0458)
It was discovered that a race condition existed in the btrfs file system
implementation in the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2023-1611)
It was discovered that the XFS file system implementation in the Linux
kernel did not properly perform metadata validation when mounting certain
images. An attacker could use this
OSV
CVE-2023-3159: A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel
osv·2023-06-12·CVSS 6.7
CVE-2023-3159 [MEDIUM] CVE-2023-3159: A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel
A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.
GHSA
GHSA-rfm6-5mxx-g3r7: A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel
ghsa_unreviewed·2023-06-12
CVE-2023-3159 [MEDIUM] CWE-416 GHSA-rfm6-5mxx-g3r7: A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel
A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.
No detection rules found.
No public exploits indexed.
2023-06-12
Published