cbcvebase.
CVE-2023-33203
published 2023-05-18

CVE-2023-33203: The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker…

medium6.4CVSS 3.1
AVPACHPRNUINSUCHIHAH
The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux_kernel< 6.2.96.2.9
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 5.4.0-156.1735.4.0-156.173
linuxlinux_kernel>= 0 < 5.15.0-79.865.15.0-79.86
msrccbl2_kernel_5.15.112.1-2_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.10.181.1-1_on_cbl_mariner_1.0
paloaltopan-os
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.4MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.5MEDIUM