CVE-2023-3439
Summary
| CVE | CVE-2023-3439 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-28 21:15:00 UTC |
| Updated | 2023-07-06 21:39:00 UTC |
| Description | A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object, potentially leading to a denial of service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| mctp: defer the kfree of object mdev->addrs · torvalds/linux@b561275 · GitHub |
MISC |
github.com |
|
| oss-security - CVE-2023-3439: Linux MCTP use-after-free in mctp_sendmsg |
MLIST |
www.openwall.com |
|
| 2217915 – (CVE-2023-3439) CVE-2023-3439 kernel: mctp: use-after-free read in mctp_local_output() |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199604 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6246-1)
- 199612 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6255-1)
- 907076 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27359-1)