CVE-2023-42938
published 2024-03-14CVE-2023-42938: A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
8.7th percentile
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | < 12.13.1 | 12.13.1 |
| apple | itunes_12.13.1_for_windows | — | — |
| apple | itunes_for_windows | >= unspecified < 12.13 | 12.13 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-chrr-r69v-42vf: A logic issue was addressed with improved checks
ghsa_unreviewed·2024-03-14
CVE-2023-42938 [HIGH] CWE-693 GHSA-chrr-r69v-42vf: A logic issue was addressed with improved checks
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.
Red Hat
kernel: loop: Fix use-after-free issues
vendor_redhat·2025-05-02·CVSS 7.8
CVE-2023-53111 [HIGH] CWE-416 kernel: loop: Fix use-after-free issues
kernel: loop: Fix use-after-free issues
In the Linux kernel, the following vulnerability has been resolved:
loop: Fix use-after-free issues
do_req_filebacked() calls blk_mq_complete_request() synchronously or
asynchronously when using asynchronous I/O unless memory allocation fails.
Hence, modify loop_handle_cmd() such that it does not dereference 'cmd' nor
'rq' after do_req_filebacked() finished unless we are sure that the request
has not yet been completed. This patch fixes the following kernel crash:
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000054
Call trace:
css_put.42938+0x1c/0x1ac
loop_process_work+0xc8c/0xfd4
loop_rootcg_workfn+0x24/0x34
process_one_work+0x244/0x558
worker_thread+0x400/0x8fc
kthread+0x16c/0x1e0
ret_from_fork+0x10/0x20
Package:
Apple
CVE-2023-42938: iTunes 12.13.1 for Windows
vendor_apple·2023-12-14·CVSS 7.8
CVE-2023-42938 [HIGH] CVE-2023-42938: iTunes 12.13.1 for Windows
Apple Security Update: About the security content of iTunes 12.13.1 for Windows
Product: iTunes 12.13.1 for Windows
CVE: CVE-2023-42938
Component: Mobile Device Service
Impact: A local attacker may be able to elevate their privileges
Description: A logic issue was addressed with improved checks.
No detection rules found.
No public exploits indexed.
2024-03-14
Published