kernel: use after free issue in driver/firewire in outbound_phy_packet_callback
Published Jun 12, 2023
6.7
MEDIUMCVSS 3.1
EPSS 0.21%
Description
A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Kernel version prior to Kernel 5.18-rc6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
- < 5.18
- 5.18
- 5.18
- 5.18
- 5.18
- 5.18
- 5.18
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2023-3159 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2213414 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-43843 Advisory
- https://github.com/torvalds/linux/commit/b7c81f80246fac44077166f3e07103affe6db8ff Patch
- https://nvd.nist.gov/vuln/detail/CVE-2023-3159
- https://www.cve.org/CVERecord?id=CVE-2023-3159
Change history (0)
No recorded changes yet.