cbcvebase.
CVE-2023-52445
published 2024-02-22

CVE-2023-52445: In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix use after free on context disconnection Upon module load, a kthread is…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
15.9th percentile
In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix use after free on context disconnection Upon module load, a kthread is created targeting the pvr2_context_thread_func function, which may call pvr2_context_destroy and thus call kfree() on the context object. However, that might happen before the usb hub_event handler is able to notify the driver. This patch adds a sanity check before the invalid read reported by syzbot, within the context disconnection call stack.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= e5be15c63804e05b5a94197524023702a259e308 < ec36c134dd020d28e312c2f1766f85525e747aabec36c134dd020d28e312c2f1766f85525e747aab
linuxlinux>= e5be15c63804e05b5a94197524023702a259e308 < 47aa8fcd5e8b5563af4042a00f25ba89bef8f33d47aa8fcd5e8b5563af4042a00f25ba89bef8f33d
linuxlinux>= e5be15c63804e05b5a94197524023702a259e308 < 3233d8bf7893550045682192cb227af7fa3defeb3233d8bf7893550045682192cb227af7fa3defeb
linuxlinux>= e5be15c63804e05b5a94197524023702a259e308 < ec3634ebe23fc3c44ebc67c6d25917300bc68c08ec3634ebe23fc3c44ebc67c6d25917300bc68c08
linuxlinux>= e5be15c63804e05b5a94197524023702a259e308 < 30773ea47d41773f9611ffb4ebc9bda9d19a9e7e30773ea47d41773f9611ffb4ebc9bda9d19a9e7e
linuxlinux>= e5be15c63804e05b5a94197524023702a259e308 < 2cf0005d315549b8d2b940ff96a66c2a889aa7952cf0005d315549b8d2b940ff96a66c2a889aa795
linuxlinux>= e5be15c63804e05b5a94197524023702a259e308 < 437b5f57732bb4cc32cc9f8895d2010ee9ff521c437b5f57732bb4cc32cc9f8895d2010ee9ff521c
linuxlinux>= e5be15c63804e05b5a94197524023702a259e308 < ded85b0c0edd8f45fec88783d7555a5b982449c1ded85b0c0edd8f45fec88783d7555a5b982449c1
linuxlinux_kernel< 4.19.3064.19.306
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.4.0-176.1965.4.0-176.196
linuxlinux_kernel>= 0 < 5.15.0-102.1125.15.0-102.112
linuxlinux_kernel>= 0 < 4.4.0-253.2874.4.0-253.287
linuxlinux_kernel>= 0 < 4.15.0-224.2364.15.0-224.236
linuxlinux_kernel>= 4.20 < 5.4.2685.4.268
linuxlinux_kernel>= 5.11.0 < 5.15.1485.15.148
linuxlinux_kernel>= 5.16.0 < 6.1.756.1.75
linuxlinux_kernel>= 5.5.0 < 5.10.2095.10.209
linuxlinux_kernel>= 6.2.0 < 6.6.146.6.14
linuxlinux_kernel>= 6.7.0 < 6.7.26.7.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.