Kernel: use after free in nvmet_tcp_free_crypto in nvme
Published Nov 1, 2023
8.8
HIGHCVSS 3.1
EPSS 9.14%
Description
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
Configuration 1
- ≥ 5.0 · < 5.4.260
- ≥ 5.5 · < 5.10.199
- ≥ 5.11 · < 5.15.137
- ≥ 5.16 · < 6.1.60
- ≥ 6.2 · < 6.5.9
Configuration 2
- 8.0
- 9.0
Configuration 3
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.9.1.el8_9
Fixed · RHSA-2023:7549
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-513.9.1.rt7.311.el8_9
Fixed · RHSA-2023:7548
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2023:7554
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.128.1.el8_2
Fixed · RHSA-2024:1268
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-0:4.18.0-193.128.1.el8_2
Fixed · RHSA-2024:1268
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-rt-0:4.18.0-193.128.1.rt13.179.el8_2
Fixed · RHSA-2024:1269
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kernel-0:4.18.0-193.128.1.el8_2
Fixed · RHSA-2024:1268
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2024:1278
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.114.1.el8_4
Fixed · RHSA-2023:7557
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-0:4.18.0-305.114.1.el8_4
Fixed · RHSA-2023:7557
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-rt-0:4.18.0-305.114.1.rt7.190.el8_4
Fixed · RHSA-2023:7551
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kernel-0:4.18.0-305.114.1.el8_4
Fixed · RHSA-2023:7557
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:7559
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 8.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:0378
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.43.1.el8_8
Fixed · RHSA-2024:0575
Red Hat Enterprise Linux 8.8 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:0554
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.18.1.el9_3
Fixed · RHSA-2024:0461
Red Hat Enterprise Linux 9
kernel-0:5.14.0-362.18.1.el9_3
Fixed · RHSA-2024:0461
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2024:0340
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.85.1.el9_0
Fixed · RHSA-2024:0432
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.85.1.rt21.156.el9_0
Fixed · RHSA-2024:0431
Red Hat Enterprise Linux 9.0 Extended Update Support
kpatch-patch
Fixed · RHSA-2024:0386
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.40.1.el9_2
Fixed · RHSA-2023:7370
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.40.1.rt14.325.el9_2
Fixed · RHSA-2023:7379
Red Hat Enterprise Linux 9.2 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:7418
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.9.1.el8_9 | Fixed | RHSA-2023:7549 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.9.1.rt7.311.el8_9 | Fixed | RHSA-2023:7548 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2023:7554 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.128.1.el8_2 | Fixed | RHSA-2024:1268 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-0:4.18.0-193.128.1.el8_2 | Fixed | RHSA-2024:1268 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-rt-0:4.18.0-193.128.1.rt13.179.el8_2 | Fixed | RHSA-2024:1269 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kernel-0:4.18.0-193.128.1.el8_2 | Fixed | RHSA-2024:1268 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2024:1278 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.114.1.el8_4 | Fixed | RHSA-2023:7557 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-0:4.18.0-305.114.1.el8_4 | Fixed | RHSA-2023:7557 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-rt-0:4.18.0-305.114.1.rt7.190.el8_4 | Fixed | RHSA-2023:7551 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kernel-0:4.18.0-305.114.1.el8_4 | Fixed | RHSA-2023:7557 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:7559 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:0378 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.43.1.el8_8 | Fixed | RHSA-2024:0575 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:0554 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.18.1.el9_3 | Fixed | RHSA-2024:0461 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.18.1.el9_3 | Fixed | RHSA-2024:0461 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2024:0340 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.85.1.el9_0 | Fixed | RHSA-2024:0432 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.85.1.rt21.156.el9_0 | Fixed | RHSA-2024:0431 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kpatch-patch | Fixed | RHSA-2024:0386 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.40.1.el9_2 | Fixed | RHSA-2023:7370 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.40.1.rt14.325.el9_2 | Fixed | RHSA-2023:7379 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:7418 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
This vulnerability is actual only for systems where NVME over TCP being used.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (29)
- https://access.redhat.com/errata/RHSA-2023:7370 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7379 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7418 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7548 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7549 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7551 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7554 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7557 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7559 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0340 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0378 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0386 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0412 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0431 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0432 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0461 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0554 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0575 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1268 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1269 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1278 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-5178 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2241924 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57515 Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00005.html
- https://lore.kernel.org/linux-nvme/20231002105428.226515-1-sagi@grimberg.me/ Mailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-5178
- https://security.netapp.com/advisory/ntap-20231208-0004/
- https://www.cve.org/CVERecord?id=CVE-2023-5178
Change history (0)
No recorded changes yet.