cbcvebase.
CVE-2023-4387
published 2023-08-16

CVE-2023-4387: A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel…

high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleaning up vmxnet3_rq_cleanup_all, which could also lead to a kernel information leak problem.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.11-1 (bookworm)linux 5.17.11-1 (bookworm)
linuxlinux_kernel>= 0 < 5.10.120-15.10.120-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 4.4.0-245.2794.4.0-245.279
linuxlinux_kernel>= 3.16.60 < 3.173.17
linuxlinux_kernel>= 4.10 < 4.14.2814.14.281
linuxlinux_kernel>= 4.15 < 4.19.2454.19.245
linuxlinux_kernel>= 4.20 < 5.4.1965.4.196
linuxlinux_kernel>= 4.4 < 4.9.3164.9.316
linuxlinux_kernel>= 5.11 < 5.15.425.15.42
linuxlinux_kernel>= 5.16 < 5.17.105.17.10
linuxlinux_kernel>= 5.5 < 5.10.1185.10.118
msrccbl2_kernel_5.15.126.1-1_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH