CVE-2023-2162: Use After Free
A use-after-free vulnerability was found in iscsiswtcpsessioncreate in drivers/scsi/iscsitcp.c in SCSI sub-component in the Linux Kernel. In this flaw an attacker could leak kernel internal information.
Other sources
Linux Kernel could allow a local attacker to obtain sensitive information, caused by a use-after-free flaw in the iscsiswtcpsessioncreate function in drivers/scsi/iscsitcp.c in the SCSI sub-component. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain kernel internal information, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2162?
CVE-2023-2162 is a high-severity use-after-free vulnerability in the Linux Kernel that can lead to leaking kernel internal information.
How do I fix CVE-2023-2162?
To mitigate CVE-2023-2162, upgrade to the latest version of the Linux Kernel or apply the latest patches provided by your distribution.
What versions of the Linux Kernel are affected by CVE-2023-2162?
CVE-2023-2162 affects versions of the Linux Kernel up to and including 6.2 and all release candidates of 6.2.
Which other products are impacted by CVE-2023-2162?
CVE-2023-2162 also affects IBM Security Verify Governance and Identity Manager software components with versions up to 10.0.2.
What are the potential impacts of CVE-2023-2162?
The exploitation of CVE-2023-2162 could lead to unauthorized access to sensitive kernel information, compromising system security.