CVE-2023-3297

HIGH

accountsservice < 23.13.9-2ubuntu2 - Use-After-Free via D-Bus Message

Title source: llm
STIX 2.1

Description

In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory
https://ubuntu.com/security/notices/USN-6190-1
Exploit, Third Party Advisory third-party-advisory technical-description
https://securitylab.github.com/advisories/GHSL-2023-139_accountsservice/
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2024182

Scores

CVSS v3 8.1
EPSS 0.0004
EPSS Percentile 13.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (5)
canonical/accountsservice < 23.13.9-2ubuntu2
canonical/ubuntu_linux 20.04
canonical/ubuntu_linux 22.04
canonical/ubuntu_linux 22.10
canonical/ubuntu_linux 23.04
Published Sep 01, 2023
Tracked Since Feb 18, 2026