Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-33203
HistoryMay 18, 2023 - 12:00 a.m.

CVE-2023-33203

2023-05-1800:00:00
ubuntu.com
ubuntu.com
23
linux kernel
race condition
qualcomm emac driver
use-after-free
physically proximate attacker
unplugging device.

6.4 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

25.4%

The Linux kernel before 6.2.9 has a race condition and resultant
use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically
proximate attacker unplugs an emac based device.

Bugs

Notes

Author Note
Priority reason: Requires driver or device to be removed or unbound, which requires either privilege or physical access.
cascardo requires driver or device to be removed
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchlinux< 5.4.0-156.173UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-79.86UNKNOWN
ubuntu23.04noarchlinux< 6.2.0-23.23UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1107.115UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1042.47UNKNOWN
ubuntu23.04noarchlinux-aws< 6.2.0-1005.5UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1041.46~20.04.1UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1107.115~18.04.1UNKNOWN
ubuntu20.04noarchlinux-azure< 5.4.0-1114.120UNKNOWN
ubuntu22.04noarchlinux-azure< 5.15.0-1045.52UNKNOWN
Rows per page:
1-10 of 591

References

6.4 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

25.4%