CVE-2023-4132

CWE-416Use After Free20 documents8 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 98.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 3
Latest updateApr 9

Description

A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service condition.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDlinux/linux_kernel6.2.16
Debianlinux< 5.10.191-1+3

Also affects: Debian Linux 10.0, 11.0, 12.0, Enterprise Linux 8.0

🔴Vulnerability Details

3
GHSA
GHSA-897q-36v3-jwhm: A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel2023-08-03
OSV
CVE-2023-4132: A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel2023-08-03
CVEList
Kernel: smsusb: use-after-free caused by do_submit_urb()2023-08-03

📋Vendor Advisories

16
Ubuntu
Linux kernel (Azure) vulnerabilities2024-04-09
Ubuntu
Linux kernel vulnerabilities2024-03-25
Ubuntu
Linux kernel (GCP) vulnerabilities2024-03-20
Ubuntu
Linux kernel vulnerabilities2024-03-18
Ubuntu
Linux kernel (StarFive) vulnerabilities2023-11-28