CVE-2023-1855: Use After Free
A use-after-free flaw was found in xgenehwmonremove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). This flaw could allow a local attacker to crash the system due to a race problem. This vulnerability could even lead to a kernel information leak problem.
Other sources
Linux Kernel is vulnerable to a denial of service, caused by a use-after-free in xgenehwmonremove in drivers/hwmon/xgene-hwmon.c in the xgene-hwmon driver. A local attacker could exploit this vulnerability to cause the system to crash or obtain kernel memory.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1855?
CVE-2023-1855 has a high severity due to its potential to cause system crashes and kernel information leaks.
How do I fix CVE-2023-1855?
To fix CVE-2023-1855, update your Kernel to version 6.3 or upgrade to specified fixed versions in Debian and IBM Security Verify components.
Which software is affected by CVE-2023-1855?
CVE-2023-1855 affects the Hardware Monitoring Linux Kernel Driver in various Linux kernel versions prior to 6.3 and specific versions of IBM Security Verify components.
Can a remote attacker exploit CVE-2023-1855?
CVE-2023-1855 is primarily a local vulnerability, meaning it requires local access to exploit the use-after-free flaw.
Is there a known workaround for CVE-2023-1855?
Currently, there is no recommended workaround for CVE-2023-1855, so applying the available updates is the best mitigation strategy.