Description
A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges.
References (2)
Core 2
Core References
Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c53b3dcb9942b8ed7f81ee3921c4085d87070c73
Third Party Advisory
https://security.netapp.com/advisory/ntap-20230420-0005/
Scores
CVSS v3
7.8
EPSS
0.0026
EPSS Percentile
17.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-416
Status
published
Products (2)
linux/linux_kernel
6.0 rc1 (3 CPE variants)
linux/linux_kernel
2.6.37 - 4.9.328
Published
Mar 22, 2023
Tracked Since
Feb 18, 2026