Record summary

CVE-2023-5178 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC.

Description

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Affected products and versions

Showing 12 of 30
ProductSourceVersion rangeStatus

Red Hat Enterprise Linux 6

Browse Red Hat / Red Hat Enterprise Linux 6kernel

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 7

Browse Red Hat / Red Hat Enterprise Linux 7kernel

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 7

Browse Red Hat / Red Hat Enterprise Linux 7kernel-rt

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8kernel

Default status: affected

CVE List0:4.18.0-513.9.1.el8_9 to < *unaffected

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8kernel-rt

Default status: affected

CVE List0:4.18.0-513.9.1.rt7.311.el8_9 to < *unaffected

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8kpatch-patch

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8.2 Advanced Update Support

Browse Red Hat / Red Hat Enterprise Linux 8.2 Advanced Update Supportkernel

Default status: affected

CVE List0:4.18.0-193.128.1.el8_2 to < *unaffected

Red Hat Enterprise Linux 8.2 Telecommunications Update Service

Browse Red Hat / Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel

Default status: affected

CVE List0:4.18.0-193.128.1.el8_2 to < *unaffected

Red Hat Enterprise Linux 8.2 Telecommunications Update Service

Browse Red Hat / Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-rt

Default status: affected

CVE List0:4.18.0-193.128.1.rt13.179.el8_2 to < *unaffected

Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions

Browse Red Hat / Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionskernel

Default status: affected

CVE List0:4.18.0-193.128.1.el8_2 to < *unaffected

Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions

Browse Red Hat / Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionskpatch-patch

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

Browse Red Hat / Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportkernel

Default status: affected

CVE List0:4.18.0-305.114.1.el8_4 to < *unaffected

Proofs of concept

1

Repository PoCs

GitHubrockrid3r/CVE-2023-5178Repository PoCby rockrid3rStars: 7Not analyzed12 files

697.3 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

Showing 12 of 27