CVE-2023-26545: Double Free
A double free in net/mpls/afmpls.c upon an allocation failure during the renaming of a device in Linux Kernel could allow a remote authenticated attacker from within the local network to cause an unknown impact.
Other sources
In the Linux kernel before 6.1.13, there is a double free in net/mpls/afmpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26545?
CVE-2023-26545 is considered to have an impact that could lead to unknown consequences due to a double free vulnerability.
How do I fix CVE-2023-26545?
To mitigate CVE-2023-26545, update the Linux Kernel to version 6.1.13 or later, or apply specific patches if available.
Which versions of the Linux Kernel are affected by CVE-2023-26545?
CVE-2023-26545 affects versions of the Linux Kernel prior to 6.1.13.
Can remote attackers exploit CVE-2023-26545?
Yes, CVE-2023-26545 allows remote authenticated attackers within the local network to exploit the vulnerability.
What types of systems are impacted by CVE-2023-26545?
CVE-2023-26545 impacts systems running affected versions of the Linux Kernel, including certain configurations of IBM Security Verify Governance and NetApp firmware.