CVE-2023-52841

MEDIUM

Linux Kernel 5.10-5.10.200 - Use-After-Free in vidtv Mux Component

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: mux: Add check and kfree for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference. Moreover, use kfree() in the later error handling in order to avoid memory leak.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401 CWE-476
Status published
Products (15)
Linux/Linux < 5.10
Linux/Linux 5.10
Linux/Linux 5.10.201 - 5.10.*
Linux/Linux 5.15.139 - 5.15.*
Linux/Linux 6.1.63 - 6.1.*
Linux/Linux 6.5.12 - 6.5.*
Linux/Linux 6.6.2 - 6.6.*
Linux/Linux 6.7
Linux/Linux c2f78f0cb294aa6f009d3a170f4ee8ad199ba5da - 1fd6eb12642e0c32692924ff359c07de4b781d78
Linux/Linux c2f78f0cb294aa6f009d3a170f4ee8ad199ba5da - 64863ba8e6b7651d994c6e6d506cc8aa2ac45edb
... and 5 more
Published May 21, 2024
Tracked Since Feb 18, 2026