CVE-2023-52702

MEDIUM

Linux Kernel 5.8-5.10.169 - Use-After-Free in OVS Meter Command Set

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible memory leak in ovs_meter_cmd_set() old_meter needs to be free after it is detached regardless of whether the new meter is successfully attached.

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 16.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (12)
Linux/Linux < 5.8
Linux/Linux 5.10.169 - 5.10.*
Linux/Linux 5.15.95 - 5.15.*
Linux/Linux 5.8
Linux/Linux 6.1.13 - 6.1.*
Linux/Linux 6.2
Linux/Linux c7c4c44c9a95d87e50ced38f7480e779cb472174 - 1563e998a938f095548054ef09e277b562b79536
Linux/Linux c7c4c44c9a95d87e50ced38f7480e779cb472174 - 2fa28f5c6fcbfc794340684f36d2581b4f2d20b5
Linux/Linux c7c4c44c9a95d87e50ced38f7480e779cb472174 - c0f65ee0a3329eb4b94beaef0268633696e2d0c6
Linux/Linux c7c4c44c9a95d87e50ced38f7480e779cb472174 - e336a9e08618203a456fb5367f1387b14554f55e
... and 2 more
Published May 21, 2024
Tracked Since Feb 18, 2026