Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-33288
HistoryMay 22, 2023 - 12:00 a.m.

CVE-2023-33288

2023-05-2200:00:00
ubuntu.com
ubuntu.com
15
linux kernel
use-after-free
bq24190_remove
local attacker
crash
race condition
bugzilla redhat
bugzilla suse
privilege
physical access

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

5.1%

An issue was discovered in the Linux kernel before 6.2.9. A use-after-free
was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It
could allow a local attacker to crash the system due to a race condition.

Bugs

Notes

Author Note
Priority reason: Requires driver or device to be removed or unbound, which requires either privilege or physical access.
cascardo requires driver or device to be removed

References

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

5.1%