CVE-2023-52653
MEDIUMLinux Kernel 2.6.35-6.8.2 - Use-After-Free in SUNRPC gss_import_v2_context
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix a memleak in gss_import_v2_context The ctx->mech_used.data allocated by kmemdup is not freed in neither gss_import_v2_context nor it only caller gss_krb5_import_sec_context, which frees ctx on error. Thus, this patch reform the last call of gss_import_v2_context to the gss_krb5_import_ctx_v2, preventing the memleak while keepping the return formation.
References (4)
Core 4
Core References
Scores
CVSS v3
5.5
EPSS
0.0027
EPSS Percentile
19.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (11)
Linux/Linux
< 2.6.35
Linux/Linux
2.6.35
Linux/Linux
47d84807762966c3611c38adecec6ea703ddda7a - 47ac11db93e74ac49cd6c3fc69bcbc5964c4a8b4
Linux/Linux
47d84807762966c3611c38adecec6ea703ddda7a - 99044c01ed5329e73651c054d8a4baacdbb1a27c
Linux/Linux
47d84807762966c3611c38adecec6ea703ddda7a - d111e30d9cd846bb368faf3637dc0f71fcbcf822
Linux/Linux
47d84807762966c3611c38adecec6ea703ddda7a - e67b652d8e8591d3b1e569dbcdfcee15993e91fa
Linux/Linux
6.6.23 - 6.6.*
Linux/Linux
6.7.11 - 6.7.*
Linux/Linux
6.8.2 - 6.8.*
Linux/Linux
6.9
... and 1 more
Published
May 01, 2024
Tracked Since
Feb 18, 2026