CVE-2023-5178
Kernel: use after free in nvmet_tcp_free_crypto in nvme
Record summary
CVE-2023-5178 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC.
Description
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
Showing 12 of 30| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: affected | CVE List | 0:4.18.0-513.9.1.el8_9 to < * | unaffected |
Default status: affected | CVE List | 0:4.18.0-513.9.1.rt7.311.el8_9 to < * | unaffected |
Default status: unaffected | CVE List | Version data not supplied | |
Red Hat Enterprise Linux 8.2 Advanced Update SupportBrowse Red Hat / Red Hat Enterprise Linux 8.2 Advanced Update SupportkernelDefault status: affected | CVE List | 0:4.18.0-193.128.1.el8_2 to < * | unaffected |
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceBrowse Red Hat / Red Hat Enterprise Linux 8.2 Telecommunications Update ServicekernelDefault status: affected | CVE List | 0:4.18.0-193.128.1.el8_2 to < * | unaffected |
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceBrowse Red Hat / Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-rtDefault status: affected | CVE List | 0:4.18.0-193.128.1.rt13.179.el8_2 to < * | unaffected |
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsBrowse Red Hat / Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionskernelDefault status: affected | CVE List | 0:4.18.0-193.128.1.el8_2 to < * | unaffected |
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsBrowse Red Hat / Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionskpatch-patchDefault status: unaffected | CVE List | Version data not supplied | |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportBrowse Red Hat / Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportkernelDefault status: affected | CVE List | 0:4.18.0-305.114.1.el8_4 to < * | unaffected |