CVE-2023-5178
published 2023-11-01CVE-2023-5178: A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux…
PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
9.14%
94.8th percentile
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.10.205-2 | 5.10.205-2 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.5.8-1 | 6.5.8-1 |
| linux | linux_kernel | >= 0 < 6.5.8-1 | 6.5.8-1 |
| linux | linux_kernel | >= 0 < 5.4.0-169.187 | 5.4.0-169.187 |
| linux | linux_kernel | >= 0 < 5.15.0-91.101 | 5.15.0-91.101 |
| linux | linux_kernel | >= 5.0 < 5.4.260 | 5.4.260 |
| linux | linux_kernel | >= 5.11 < 5.15.137 | 5.15.137 |
| linux | linux_kernel | >= 5.16 < 6.1.60 | 6.1.60 |
| linux | linux_kernel | >= 5.5 < 5.10.199 | 5.10.199 |
| linux | linux_kernel | >= 6.2 < 6.5.9 | 6.5.9 |
| msrc | cbl2_hyperv-daemons_5.15.137.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.138.1-4_on_cbl_mariner_2.0 | — | — |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| ubuntu | linux-gcp | — | — |
| ubuntu | linux-kvm | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is only exploitable on systems where NVMe over TCP (NVMe-oF/TCP) is actively in use; scope detection to hosts with NVMe/TCP enabled ↗
- →The vulnerable code path is in drivers/nvme/target/tcp.c, specifically in the nvmet_tcp_free_crypto function; monitor kernel crash/UAF reports originating from this function ↗
- →The vulnerability can be triggered remotely via queue initialization failures in NVMe-oF/TCP; monitor for anomalous NVMe-oF/TCP connection attempts or queue setup errors from untrusted sources ↗
- →Upstream patch reference available for signature/diff-based detection; review the patch at the linked lore.kernel.org thread ↗
- ·Exploitation requires NVMe-oF/TCP to be in use; systems not running NVMe over TCP are not affected ↗
- ·Remote exploitation is possible (denial of service or RCE); local privilege escalation is also a potential outcome if the attacker already has local access ↗
- ·Red Hat Enterprise Linux 6 and 7 (including kernel-rt) are confirmed not affected; RHEL 8 and 9 (including kernel-rt on RHEL 9) are affected ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC OS
cisa_ics·2025-08-14
Siemens SINEC OS
ICS Advisory
##
Siemens SINEC OS
Release DateAugust 14, 2025
Alert CodeICSA-25-226-15
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3.1 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM, SCALANCE
- Vulnerabilities: NULL Pointer Dereference, Use After Free, Unchecked Input for Loop Condition, Out-of-bounds Write, Ou
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Linux kernel (GCP) vulnerabilities
vendor_ubuntu·2024-02-14·CVSS 4.6
CVE-2023-37453 [MEDIUM] Linux kernel (GCP) vulnerabilities
Title: Linux kernel (GCP) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Sunjoo Park discovered that the netfilter subsystem in the Linux kernel did
not properly validate u32 pack
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-01-10·CVSS 4.6
CVE-2023-39192 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in t
Ubuntu
Linux kernel (IoT) vulnerabilities
vendor_ubuntu·2024-01-10·CVSS 5.5
CVE-2023-6176 [MEDIUM] Linux kernel (IoT) vulnerabilities
Title: Linux kernel (IoT) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
po
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2024-01-09·CVSS 5.1
CVE-2023-5178 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Yikebaer Aizezi discovered that the ext4 file system implementation in the
Linu
Ubuntu
Linux kernel (GKE) vulnerabilities
vendor_ubuntu·2024-01-09·CVSS 5.5
CVE-2023-3006 [MEDIUM] Linux kernel (GKE) vulnerabilities
Title: Linux kernel (GKE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
po
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities
vendor_ubuntu·2024-01-05·CVSS 4.6
CVE-2023-39189 [MEDIUM] Linux kernel (Intel IoTG) vulnerabilities
Title: Linux kernel (Intel IoTG) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter s
Ubuntu
Linux kernel (Low Latency) vulnerabilities
vendor_ubuntu·2023-12-13·CVSS 4.6
CVE-2023-5178 [MEDIUM] Linux kernel (Low Latency) vulnerabilities
Title: Linux kernel (Low Latency) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-12-13·CVSS 4.6
CVE-2023-5178 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in t
Ubuntu
Linux kernel (Oracle) vulnerabilities
vendor_ubuntu·2023-12-13·CVSS 5.5
CVE-2023-5178 [MEDIUM] Linux kernel (Oracle) vulnerabilities
Title: Linux kernel (Oracle) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-12-12·CVSS 5.5
CVE-2023-39194 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly
Ubuntu
Linux kernel (GKE) vulnerabilities
vendor_ubuntu·2023-12-12·CVSS 4.6
CVE-2023-5717 [MEDIUM] Linux kernel (GKE) vulnerabilities
Title: Linux kernel (GKE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsyste
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-12-12·CVSS 4.6
CVE-2023-5158 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-12-11·CVSS 4.6
CVE-2023-5178 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-12-06·CVSS 5.1
CVE-2023-5158 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Yikebaer Aizezi discovered that the ext4 file system implementation in the
Linux kernel
Ubuntu
Linux kernel (GCP) vulnerabilities
vendor_ubuntu·2023-12-06·CVSS 5.5
CVE-2023-5158 [MEDIUM] Linux kernel (GCP) vulnerabilities
Title: Linux kernel (GCP) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Yu Hao discovered that the UBI driver in the Linux kernel did not properly
check for MTD with zero erasesize during device attachment. A local
privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-31085)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Bien Pham discovered that the netfiler subsystem in the Linux kernel
contained a race condition, leading to a use-after-free vulnerability. A
local user could us
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-12-05·CVSS 4.6
CVE-2023-5158 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in t
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2023-11-21·CVSS 6.0
CVE-2023-5090 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Maxim Levitsky discovered that the KVM nested virtualization (SVM)
implementation for AMD processors in the Linux kernel did not properly
handle x2AVIC MSRs. An attacker in a guest VM could use this to cause a
denial of service (host kernel crash). (CVE-2023-5090)
Alon Zahavi discovered that the NVMe-oF/TCP subsystem in the Linux kernel
did not properly handle queue initialization failures in certain
situations, leading to a use-after-free vulnerability. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2023-5178)
Budimir Markovic discovered that the perf subsystem in the Linux kernel
did not properly handle event
Microsoft
Kernel: use after free in nvmet_tcp_free_crypto in nvme
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5178 [HIGH] CWE-416 Kernel: use after free in nvmet_tcp_free_crypto in nvme
Kernel: use after free in nvmet_tcp_free_crypto in nvme
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://lea
Red Hat
kernel: use after free in nvmet_tcp_free_crypto in NVMe
vendor_redhat·2023-10-15·CVSS 8.8
CVE-2023-5178 [HIGH] CWE-416 kernel: use after free in nvmet_tcp_free_crypto in NVMe
kernel: use after free in nvmet_tcp_free_crypto in NVMe
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
Statement: This vulnerability is actual only for systems where NVME over TC
Debian
CVE-2023-5178: linux - A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet...
vendor_debian·2023·CVSS 8.8
CVE-2023-5178 [HIGH] CVE-2023-5178: linux - A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet...
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved (fixed in 5.10.205-2)
forky: resolved (fixed in 6.5.8-1)
sid: resolved (fixed in 6.5.8-1)
trixie: resolved (fixed in 6.5.8-1)
OSV
linux-gcp-6.2 vulnerabilities
osv·2024-02-14·CVSS 4.6
CVE-2023-37453 [MEDIUM] linux-gcp-6.2 vulnerabilities
linux-gcp-6.2 vulnerabilities
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Sunjoo Park discovered that the netfilter subsystem in the Linux kernel did
not properly validate u32 packets content, leading to an out-of-bounds read
vulnerability. A local attacker
OSV
linux-iot vulnerabilities
osv·2024-01-10·CVSS 5.5
CVE-2023-3006 [MEDIUM] linux-iot vulnerabilities
linux-iot vulnerabilities
It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Sunjoo Park
OSV
linux-gcp-5.15, linux-intel-iotg-5.15 vulnerabilities
osv·2024-01-10·CVSS 4.6
CVE-2023-37453 [MEDIUM] linux-gcp-5.15, linux-intel-iotg-5.15 vulnerabilities
linux-gcp-5.15, linux-intel-iotg-5.15 vulnerabilities
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some a
OSV
linux-gkeop vulnerabilities
osv·2024-01-09·CVSS 5.5
CVE-2023-3006 [MEDIUM] linux-gkeop vulnerabilities
linux-gkeop vulnerabilities
It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Sunjoo Pa
OSV
linux-azure vulnerabilities
osv·2024-01-09·CVSS 6.0
CVE-2023-39189 [MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Yikebaer Aizezi discovered that the ext4 file system implementation in the
Linux kernel contained a use-after-free vulnerability when handling inode
extent metad
OSV
linux-intel-iotg vulnerabilities
osv·2024-01-05·CVSS 4.6
CVE-2023-37453 [MEDIUM] linux-intel-iotg vulnerabilities
linux-intel-iotg vulnerabilities
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from
OSV
linux-hwe-6.2, linux-lowlatency-hwe-6.2, linux-nvidia-6.2 vulnerabilities
osv·2023-12-13·CVSS 4.6
CVE-2023-37453 [MEDIUM] linux-hwe-6.2, linux-lowlatency-hwe-6.2, linux-nvidia-6.2 vulnerabilities
linux-hwe-6.2, linux-lowlatency-hwe-6.2, linux-nvidia-6.2 vulnerabilities
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not prop
OSV
linux-lowlatency, linux-lowlatency-hwe-5.15 vulnerabilities
osv·2023-12-13·CVSS 4.6
CVE-2023-37453 [MEDIUM] linux-lowlatency, linux-lowlatency-hwe-5.15 vulnerabilities
linux-lowlatency, linux-lowlatency-hwe-5.15 vulnerabilities
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate
OSV
linux-oracle vulnerabilities
osv·2023-12-13·CVSS 5.5
CVE-2023-3006 [MEDIUM] linux-oracle vulnerabilities
linux-oracle vulnerabilities
It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Sunjoo P
OSV
linux-gkeop, linux-gkeop-5.15 vulnerabilities
osv·2023-12-12·CVSS 4.6
CVE-2023-37453 [MEDIUM] linux-gkeop, linux-gkeop-5.15 vulnerabilities
linux-gkeop, linux-gkeop-5.15 vulnerabilities
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attribute
OSV
linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities
osv·2023-12-12·CVSS 5.5
CVE-2023-3006 [MEDIUM] linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities
linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities
It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel m
OSV
linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gke, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-kvm, linux-nvidia, linux-
osv·2023-12-11·CVSS 4.6
[MEDIUM] linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gke, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-kvm, linux-nvidia, linux-
linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gke, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-kvm, linux-nvidia, linux-oracle, linux-oracle-5.15, linux-raspi vulnerabilities
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of s
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-xilinx-zynqmp vulnerabilities
osv·2023-12-11·CVSS 5.5
CVE-2023-3006 [MEDIUM] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-xilinx-zynqmp vulnerabilities
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-xilinx-zynqmp vulnerabilities
It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from usersp
OSV
linux-gcp vulnerabilities
osv·2023-12-06·CVSS 5.5
CVE-2023-31085 [MEDIUM] linux-gcp vulnerabilities
linux-gcp vulnerabilities
Yu Hao discovered that the UBI driver in the Linux kernel did not properly
check for MTD with zero erasesize during device attachment. A local
privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-31085)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Bien Pham discovered that the netfiler subsystem in the Linux kernel
contained a race condition, leading to a use-after-free vulnerability. A
local user could use this to cause a denial of service (system crash) or
possibly execute arbitrary c
OSV
linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
osv·2023-12-06·CVSS 6.0
CVE-2023-39189 [MEDIUM] linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-2023-39189)
Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did
not properly handle socket buffers (skb) when performing IP routing in
certain circumstances, leading to a null pointer dereference vulnerability.
A privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-42754)
Yikebaer Aizezi discovered that the ext4 file system implementatio
OSV
linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-lowlatency, linux-oracle, linux-raspi, linux-starfive vulnerabilities
osv·2023-12-05·CVSS 4.6
CVE-2023-37453 [MEDIUM] linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-lowlatency, linux-oracle, linux-raspi, linux-starfive vulnerabilities
linux, linux-aws, linux-aws-6.2, linux-azure, linux-azure-6.2, linux-azure-fde-6.2, linux-lowlatency, linux-oracle, linux-raspi, linux-starfive vulnerabilities
It was discovered that the USB subsystem in the Linux kernel contained a
race condition while handling device descriptors in certain situations,
leading to a out-of-bounds read vulnerability. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-37453)
Lin Ma discovered that the Netlink Transformation (XFRM) subsystem in the
Linux kernel did not properly initialize a policy data structure, leading
to an out-of-bounds vulnerability. A local privileged attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information (kernel memory). (CVE-2023-3773)
OSV
linux-oem-6.1 vulnerabilities
osv·2023-11-21·CVSS 5.5
CVE-2023-5090 [MEDIUM] linux-oem-6.1 vulnerabilities
linux-oem-6.1 vulnerabilities
Maxim Levitsky discovered that the KVM nested virtualization (SVM)
implementation for AMD processors in the Linux kernel did not properly
handle x2AVIC MSRs. An attacker in a guest VM could use this to cause a
denial of service (host kernel crash). (CVE-2023-5090)
Alon Zahavi discovered that the NVMe-oF/TCP subsystem in the Linux kernel
did not properly handle queue initialization failures in certain
situations, leading to a use-after-free vulnerability. A remote attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2023-5178)
Budimir Markovic discovered that the perf subsystem in the Linux kernel
did not properly handle event groups, leading to an out-of-bounds write
vulnerability. A local attacker cou
GHSA
GHSA-xr9j-c7v6-7542: A use-after-free vulnerability was found in drivers/nvme/target/tcp
ghsa_unreviewed·2023-11-01
CVE-2023-5178 [HIGH] CWE-1341 GHSA-xr9j-c7v6-7542: A use-after-free vulnerability was found in drivers/nvme/target/tcp
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation in case that the attacker already has local privileges.
OSV
CVE-2023-5178: A use-after-free vulnerability was found in drivers/nvme/target/tcp
osv·2023-11-01·CVSS 8.8
CVE-2023-5178 [HIGH] CVE-2023-5178: A use-after-free vulnerability was found in drivers/nvme/target/tcp
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-5178 kernel: use after free in nvmet_tcp_free_crypto in NVMe
bugzilla·2023-10-03·CVSS 8.8
CVE-2023-5178 [HIGH] CVE-2023-5178 kernel: use after free in nvmet_tcp_free_crypto in NVMe
CVE-2023-5178 kernel: use after free in nvmet_tcp_free_crypto in NVMe
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe-oF/TCP subsystem in the Linux kernel. In this flaw, a malicious user can cause a UAF and a double free, which may lead to RCE (may also lead to an LPE in case the attacker already has local privileges).
Reference:
https://lore.kernel.org/linux-nvme/[email protected]/
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2023:7379 https://access.redhat.com/errata/RHSA-2023:7379
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Supp
Bugzilla
CVE-2022-48174 busybox: stack overflow vulnerability in ash.c leads to arbitrary code execution
bugzilla·2023-09-04·CVSS 9.8
CVE-2022-48174 [CRITICAL] CVE-2022-48174 busybox: stack overflow vulnerability in ash.c leads to arbitrary code execution
CVE-2022-48174 busybox: stack overflow vulnerability in ash.c leads to arbitrary code execution
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
https://bugs.busybox.net/show_bug.cgi?id=15216
Discussion:
Created busybox tracking bugs for this issue:
Affects: fedora-all [bug 2237154]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Extended Lifecycle Support
Via RHSA-2023:5178 https://access.redhat.com/errata/RHSA-2023:5178
https://access.redhat.com/errata/RHSA-2023:7370https://access.redhat.com/errata/RHSA-2023:7379https://access.redhat.com/errata/RHSA-2023:7418https://access.redhat.com/errata/RHSA-2023:7548https://access.redhat.com/errata/RHSA-2023:7549https://access.redhat.com/errata/RHSA-2023:7551https://access.redhat.com/errata/RHSA-2023:7554https://access.redhat.com/errata/RHSA-2023:7557https://access.redhat.com/errata/RHSA-2023:7559https://access.redhat.com/errata/RHSA-2024:0340https://access.redhat.com/errata/RHSA-2024:0378https://access.redhat.com/errata/RHSA-2024:0386https://access.redhat.com/errata/RHSA-2024:0412https://access.redhat.com/errata/RHSA-2024:0431https://access.redhat.com/errata/RHSA-2024:0432https://access.redhat.com/errata/RHSA-2024:0461https://access.redhat.com/errata/RHSA-2024:0554https://access.redhat.com/errata/RHSA-2024:0575https://access.redhat.com/errata/RHSA-2024:1268https://access.redhat.com/errata/RHSA-2024:1269https://access.redhat.com/errata/RHSA-2024:1278https://access.redhat.com/security/cve/CVE-2023-5178https://bugzilla.redhat.com/show_bug.cgi?id=2241924https://lore.kernel.org/linux-nvme/[email protected]/https://access.redhat.com/errata/RHSA-2023:7370https://access.redhat.com/errata/RHSA-2023:7379https://access.redhat.com/errata/RHSA-2023:7418https://access.redhat.com/errata/RHSA-2023:7548https://access.redhat.com/errata/RHSA-2023:7549https://access.redhat.com/errata/RHSA-2023:7551https://access.redhat.com/errata/RHSA-2023:7554https://access.redhat.com/errata/RHSA-2023:7557https://access.redhat.com/errata/RHSA-2023:7559https://access.redhat.com/errata/RHSA-2024:0340https://access.redhat.com/errata/RHSA-2024:0378https://access.redhat.com/errata/RHSA-2024:0386https://access.redhat.com/errata/RHSA-2024:0412https://access.redhat.com/errata/RHSA-2024:0431https://access.redhat.com/errata/RHSA-2024:0432https://access.redhat.com/errata/RHSA-2024:0461https://access.redhat.com/errata/RHSA-2024:0554https://access.redhat.com/errata/RHSA-2024:0575https://access.redhat.com/errata/RHSA-2024:1268https://access.redhat.com/errata/RHSA-2024:1269https://access.redhat.com/errata/RHSA-2024:1278https://access.redhat.com/security/cve/CVE-2023-5178https://bugzilla.redhat.com/show_bug.cgi?id=2241924https://lists.debian.org/debian-lts-announce/2024/01/msg00005.htmlhttps://lore.kernel.org/linux-nvme/[email protected]/https://security.netapp.com/advisory/ntap-20231208-0004/
2023-11-01
Published