cbcvebase.
CVE-2023-52509
published 2024-03-02

CVE-2023-52509: In the Linux kernel, the following vulnerability has been resolved: ravb: Fix use-after-free issue in ravb_tx_timeout_work() The ravb_stop() should call…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.5th percentile
In the Linux kernel, the following vulnerability has been resolved:

ravb: Fix use-after-free issue in ravb_tx_timeout_work()

The ravb_stop() should call cancel_work_sync(). Otherwise,
ravb_tx_timeout_work() is possible to use the freed priv after
ravb_remove() was called like below:

CPU0 CPU1
ravb_tx_timeout()
ravb_remove()
unregister_netdev()
free_netdev(ndev)
// free priv
ravb_tx_timeout_work()
// use priv

unregister_netdev() will call .ndo_stop() so that ravb_stop() is
called. And, after phy_stop() is called, netif_carrier_off()
is also called. So that .ndo_tx_timeout() will not be called
after phy_stop().

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= c156633f1353264634135dea86ffcae74f2122fc < 65d34cfd4e347054eb4193bc95d9da7eaa72dee565d34cfd4e347054eb4193bc95d9da7eaa72dee5
linuxlinux>= c156633f1353264634135dea86ffcae74f2122fc < db9aafa19547833240f58c2998aed7baf414dc82db9aafa19547833240f58c2998aed7baf414dc82
linuxlinux>= c156633f1353264634135dea86ffcae74f2122fc < 616761cf9df9af838c0a1a1232a69322a9eb67e6616761cf9df9af838c0a1a1232a69322a9eb67e6
linuxlinux>= c156633f1353264634135dea86ffcae74f2122fc < 6f6fa8061f756aedb93af12a8a5d3cf6591279656f6fa8061f756aedb93af12a8a5d3cf659127965
linuxlinux>= c156633f1353264634135dea86ffcae74f2122fc < 105abd68ad8f781985113aee2e92e0702b133705105abd68ad8f781985113aee2e92e0702b133705
linuxlinux>= c156633f1353264634135dea86ffcae74f2122fc < 3971442870713de527684398416970cf025b4f893971442870713de527684398416970cf025b4f89
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 4.4.0-262.2964.4.0-262.296
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244
linuxlinux_kernel>= 4.2 < 5.4.2595.4.259
linuxlinux_kernel>= 5.11 < 5.15.1365.15.136
linuxlinux_kernel>= 5.16 < 6.1.596.1.59
linuxlinux_kernel>= 5.5 < 5.10.1995.10.199
linuxlinux_kernel>= 6.2 < 6.5.86.5.8

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.