Lucene search

K
cvelistRedhatCVELIST:CVE-2023-1838
HistoryApr 05, 2023 - 12:00 a.m.

CVE-2023-1838

2023-04-0500:00:00
CWE-416
redhat
www.cve.org
2
vhost_net_set_backend
virtio network
linux kernel
double fget
local attacker
crash
kernel information leak

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash the system, and could even lead to a kernel information leak problem.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Kernel",
    "versions": [
      {
        "version": "Linux Kernel prior to kernel 5.18 25",
        "status": "affected"
      }
    ]
  }
]