CVE-2023-5345
Summary
| CVE | CVE-2023-5345 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-03 03:15:00 UTC |
| Updated | 2023-10-24 17:51:00 UTC |
| Description | A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation.
In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free.
We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| [SECURITY] Fedora 38 Update: kernel-6.5.6-200.fc38 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: kernel-6.5.6-100.fc37 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 39 Update: kernel-6.5.6-300.fc39 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| kernel.dance/e6e43b8aa7cd3c3af686caf0c2e11819a886d705 |
MISC |
kernel.dance |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161236 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-13047)
- 161256 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-7749)
- 199881 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6461-1)
- 199933 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6502-1)
- 199938 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6503-1)
- 199952 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-6502-2)
- 199957 Ubuntu Security Notification for Linux kernel (StarFive) Vulnerabilities (USN-6520-1)
- 199958 Ubuntu Security Notification for Linux kernel (NVIDIA) Vulnerabilities (USN-6502-3)
- 199973 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6502-4)
- 199982 Ubuntu Security Notification for Linux kernel (GCP) Vulnerability (USN-6537-1)
- 200074 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-6607-1)
- 242561 Red Hat Update for kpatch-patch (RHSA-2023:7734)
- 242575 Red Hat Update for kernel (RHSA-2023:7749)
- 284598 Fedora Security Update for kernel (FEDORA-2023-50bd7c9c12)
- 284599 Fedora Security Update for kernel (FEDORA-2023-830d9ec624)
- 285211 Fedora Security Update for kernel (FEDORA-2023-c3bb819677)
- 356530 Amazon Linux Security Advisory for kernel : ALAS2023-2023-385
- 6140013 AWS Bottlerocket Security Update for kernel (GHSA-868r-x68r-5c5p)
- 6140175 AWS Bottlerocket Security Update for kernel (GHSA-868r-x68r-5c5p)
- 755059 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4035-1)
- 755082 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4058-1)
- 755083 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4057-1)
- 755085 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4072-1)
- 755086 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4071-1)
- 755096 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4093-1)
- 755229 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4072-2)
- 755399 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 5 for SLE 15 SP5) (SUSE-SU-2023:4775-1)
- 755401 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 3 for SLE 15 SP5) (SUSE-SU-2023:4766-1)
- 755413 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 18 for SLE 15 SP4) (SUSE-SU-2023:4801-1)
- 755414 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 1 for SLE 15 SP5) (SUSE-SU-2023:4805-1)
- 755418 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 11 for SLE 15 SP4) (SUSE-SU-2023:4822-1)
- 755420 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 2 for SLE 15 SP5) (SUSE-SU-2023:4841-1)
- 755466 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 5 for SLE 15 SP5) (SUSE-SU-2023:4863-1)
- 755470 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 3 for SLE 15 SP5) (SUSE-SU-2023:4848-1)
- 755474 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 16 for SLE 15 SP4) (SUSE-SU-2023:4872-1)
- 907538 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (31149-1)
- 907578 Common Base Linux Mariner (CBL-Mariner) Security Update for hyperv-daemons (31730-1)