Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-3141
HistoryJun 09, 2023 - 12:00 a.m.

CVE-2023-3141

2023-06-0900:00:00
ubuntu.com
ubuntu.com
15
cve-2023-3141
use-after-free flaw
media access
linux kernel
local attacker
device disconnect
kernel information leak
module unload

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

A use-after-free flaw was found in r592_remove in
drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw
allows a local attacker to crash the system at device disconnect, possibly
leading to a kernel information leak.

Notes

Author Note
sbeattie occurs on module unload, dropping priority to low. break commit is when the device driver was introduced; issue may have been introduced at some point later.
Rows per page:
1-10 of 811

References

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%