CVE-2023-45898
published 2023-10-16CVE-2023-45898: The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.6th percentile
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.5.6-1 (forky) | linux 6.5.6-1 (forky) |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 6.5 < 6.5.4 | 6.5.4 |
| msrc | cbl2_kernel_5.15.135.1-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500
cisa_ics·2024-04-11
Siemens SIMATIC S7-1500
ICS Advisory
##
Siemens SIMATIC S7-1500
Release DateApril 11, 2024
Alert CodeICSA-24-102-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500
- Vulnerabilities: Improper Check for Unusual or Exceptional Conditions, Improper Input Validation, Use After Free, Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2024-01-09·CVSS 5.1
CVE-2023-5178 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Yikebaer Aizezi discovered that the ext4 file system implementation in the
Linu
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-12-06·CVSS 5.1
CVE-2023-5158 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Yikebaer Aizezi discovered that the ext4 file system implementation in the
Linux kernel
Ubuntu
Linux kernel (GCP) vulnerabilities
vendor_ubuntu·2023-12-06·CVSS 5.5
CVE-2023-5158 [MEDIUM] Linux kernel (GCP) vulnerabilities
Title: Linux kernel (GCP) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Yu Hao discovered that the UBI driver in the Linux kernel did not properly
check for MTD with zero erasesize during device attachment. A local
privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-31085)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Bien Pham discovered that the netfiler subsystem in the Linux kernel
contained a race condition, leading to a use-after-free vulnerability. A
local user could us
Red Hat
kernel: use-after-free in fs/ext4/extents_status.c
vendor_redhat·2023-10-23·CVSS 7.8
CVE-2023-45898 [HIGH] CWE-416 kernel: use-after-free in fs/ext4/extents_status.c
kernel: use-after-free in fs/ext4/extents_status.c
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
A use-after-free flaw was found in the EXT4 file system, related to ext4_es_insert_extent, in the Linux Kernel. This issue may allow an attacker to create a crafted EXT4 file system which will trigger the vulnerability and lead the kernel to PANIC, causing a denial of service on the targeted system.
Statement: The Red Hat Enterprise Linux (all versions) not affected, because previous commit 2a69c45 not applied yet (that is "ext4: using nofail preallocation in ext4_es_insert_extent()").
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kern
Microsoft
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c related to ext4_es_insert_extent.
vendor_msrc·2023-10-10·CVSS 7.8
CVE-2023-45898 [HIGH] CWE-416 The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c related to ext4_es_insert_extent.
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c related to ext4_es_insert_extent.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Ye
Debian
CVE-2023-45898: linux - The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_statu...
vendor_debian·2023·CVSS 7.8
CVE-2023-45898 [HIGH] CVE-2023-45898: linux - The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_statu...
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.5.6-1)
sid: resolved (fixed in 6.5.6-1)
trixie: resolved (fixed in 6.5.6-1)
OSV
linux-azure vulnerabilities
osv·2024-01-09·CVSS 6.0
CVE-2023-39189 [MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Yikebaer Aizezi discovered that the ext4 file system implementation in the
Linux kernel contained a use-after-free vulnerability when handling inode
extent metad
OSV
linux-gcp vulnerabilities
osv·2023-12-06·CVSS 5.5
CVE-2023-31085 [MEDIUM] linux-gcp vulnerabilities
linux-gcp vulnerabilities
Yu Hao discovered that the UBI driver in the Linux kernel did not properly
check for MTD with zero erasesize during device attachment. A local
privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-31085)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Bien Pham discovered that the netfiler subsystem in the Linux kernel
contained a race condition, leading to a use-after-free vulnerability. A
local user could use this to cause a denial of service (system crash) or
possibly execute arbitrary c
OSV
linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
osv·2023-12-06·CVSS 6.0
CVE-2023-39189 [MEDIUM] linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Yikebaer Aizezi discovered that the ext4 file system implementatio
OSV
CVE-2023-45898: The Linux kernel before 6
osv·2023-10-16·CVSS 7.8
CVE-2023-45898 [HIGH] CVE-2023-45898: The Linux kernel before 6
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
GHSA
GHSA-3x3x-vjcr-56cc: The Linux kernel before 6
ghsa_unreviewed·2023-10-16
CVE-2023-45898 [HIGH] CWE-416 GHSA-3x3x-vjcr-56cc: The Linux kernel before 6
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
No detection rules found.
No public exploits indexed.
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.4https://github.com/torvalds/linux/commit/768d612f79822d30a1e7d132a4d4b05337ce42echttps://lkml.org/lkml/2023/8/13/477https://lore.kernel.org/lkml/aa03f191-445c-0d2e-d6d7-0a3208d7df7a%40huawei.com/T/https://www.spinics.net/lists/stable-commits/msg317086.htmlhttps://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.4https://github.com/torvalds/linux/commit/768d612f79822d30a1e7d132a4d4b05337ce42echttps://lkml.org/lkml/2023/8/13/477https://lore.kernel.org/lkml/aa03f191-445c-0d2e-d6d7-0a3208d7df7a%40huawei.com/T/https://www.spinics.net/lists/stable-commits/msg317086.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-398330.html
2023-10-16
Published