Lucene search

K
cvelistMitreCVELIST:CVE-2023-28466
HistoryMar 15, 2023 - 12:00 a.m.

CVE-2023-28466

2023-03-1500:00:00
mitre
www.cve.org
2
linux
kernel
tls
vulnerability
race condition
use-after-free
null pointer
dereference

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).