CVE-2023-1838

🟡 Monitoruj

Błąd use-after-free w kernelu Linux umożliwia lokalnemu atakującemu awarię systemu.

CVSS
7.1
EPSS
0.3%
Exploit
none
Vendor
linux
Opis źródłowy (NVD)

A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash the system, and could even lead to a kernel information leak problem.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2023-04-05 19:15:07 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:17:22 UTC
Referencje