CVE-2023-37454
MEDIUMLinux Kernel < 6.4.2 - Use-After-Free in UDF Filesystem Superblock Handling
Title source: llmDescription
An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective about this.
References (6)
Core 6
Core References
Exploit, Mailing List, Third Party Advisory
https://syzkaller.appspot.com/bug?extid=26873a72980f8fa8bc55
Exploit, Mailing List, Third Party Advisory
https://syzkaller.appspot.com/bug?extid=60864ed35b1073540d57
Exploit, Mailing List, Third Party Advisory
https://syzkaller.appspot.com/bug?extid=61564e5023b7229ec85d
Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-37454
Scores
CVSS v3
5.5
EPSS
0.0036
EPSS Percentile
28.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (1)
linux/linux_kernel
< 6.4.2
Published
Jul 06, 2023
Tracked Since
Feb 18, 2026