CVE-2023-3141: Use After Free
A use-after-free flaw was found in r592remove in drivers/memstick/host/r592.c in media access in Linux Kernel. This flaw could allow a local attacker to crash the system at device disconnect. This vulnerability could even lead to a kernel information leak problem.
Refer: https://lore.kernel.org/lkml/CAPDyKFoV9aZObZ5GBm0U-UVeVkBNrAG-kH3BKoP4EXdYM4bw@mail.gmail.com/t/
Other sources
A use-after-free flaw was found in r592remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.
— Launchpad
Linux Kernel is vulnerable to a denial of service, caused by a use-after-free in r592remove in drivers/memstick/host/r592.c in media access. An attacker could exploit this vulnerability to crash the system at device disconnect and possibly leak kernel information.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/Kernelto a version that resolves this vulnerability.Fixed in 6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3141?
CVE-2023-3141 is considered to be of high severity due to its potential to allow local attackers to crash the system and cause a kernel information leak.
How do I fix CVE-2023-3141?
To remediate CVE-2023-3141, update to the kernel version 6.4 or later where this vulnerability is addressed.
Which systems are affected by CVE-2023-3141?
CVE-2023-3141 affects various versions of the Linux Kernel, and specific software components from IBM and NetApp.
Can CVE-2023-3141 be exploited remotely?
CVE-2023-3141 is deemed a local vulnerability, requiring an attacker to have local access to the affected system to exploit it.
What symptoms might indicate a CVE-2023-3141 exploit?
Symptoms of an exploit of CVE-2023-3141 may include system crashes or unexpected behavior when disconnecting devices.