CVE-2023-35824: Use After Free
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105remove in drivers/media/pci/dm1105/dm1105.c.
Other sources
Linux Kernel could allow a local authenticated attacker to execute arbitrary code on the system, caused by a use-after-free flaw in the dm1105remove function in drivers/media/pci/dm1105/dm1105.c. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.4 - Upgrade
Upgrade
linux kernelto a version that resolves this vulnerability.Fixed in 6.3.2Patch 49bb0b6a-e669-d4e7-d742-a19d2763e947@xs4all.nl - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 5abda7a16698d4d1f47af1168d8fa2c640116b4a
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35824?
CVE-2023-35824 is classified as a high-severity vulnerability due to the use-after-free condition in the Linux kernel.
How do I fix CVE-2023-35824?
To mitigate CVE-2023-35824, update the Linux kernel to version 6.4 or later.
Which systems are affected by CVE-2023-35824?
CVE-2023-35824 affects Linux kernel versions before 6.3.2 and specific products like IBM Security Verify Governance.
What kind of vulnerability is CVE-2023-35824?
CVE-2023-35824 is a use-after-free vulnerability found in the dm1105 driver of the Linux kernel.
Is there a workaround for CVE-2023-35824?
There is no officially recommended workaround for CVE-2023-35824; updating the kernel is the best mitigation strategy.