CVE-2023-1192
CVSS V2 None
CVSS V3 None
Description
A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a denial of service.
Overview
- CVE ID
- CVE-2023-1192
- Assigner
- redhat
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-11-01T19:01:47.336Z
- Last Modified Date
- 2024-03-07T16:42:37.540Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2023-1192 | vdb-entry x_refsource_REDHAT |
https://bugzilla.redhat.com/show_bug.cgi?id=2154178 | issue-tracking x_refsource_REDHAT |
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d527f51331cace562393a8038d870b3e9916686f |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-1192 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1192 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 08:44:14 | Added to TrackCVE |