CVE-2023-35825: Use After Free

Published Jun 18, 2023
·
Updated

REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-3141. Reason: This candidate is a reservation duplicate of CVE-2023-3141. Notes: All CVE users should reference CVE-2023-3141 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

Other sources

An issue was discovered in the Linux kernel before 6.3.4. A use-after-free was found in r592remove in drivers/memstick/host/r592.c.

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=63264422785021704c39b38f65a78ab9e4a186d7 https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.4 https://lore.kernel.org/lkml/20230501030540.3254928-4-sashal@kernel.org/ https://lore.kernel.org/all/20230523164950.435226211@linuxfoundation.org/

Red Hat

Linux Kernel could allow a local authenticated attacker to execute arbitrary code on the system, caused by a use-after-free flaw in the r592remove function in drivers/memstick/host/r592.c. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.

IBM

Affected Software

3 affected componentsFixes available
IBM Security Verify Governance, Identity Manager software component<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager virtual appliance component<=ISVG 10.0.2
redhat/kernel<6.4
6.4

Event History

Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jun 18, 2023
CVE Published
10:15 PM
Rejected
10:15 PM
Data Sourced
10:15 PM
Description
Jun 19, 2023
Rejected
via MITRE·12:00 AM
Data Sourced
via Red Hat·06:18 AM
DescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-35825?

CVE-2023-35825 is marked as a duplicate and does not have a severity rating since it should be referenced to CVE-2023-3141.

2

How do I fix CVE-2023-35825?

Since CVE-2023-35825 is a duplicate, fixes should be sought in the patches or updates related to CVE-2023-3141.

3

Which software is affected by CVE-2023-35825?

CVE-2023-35825 affects Red Hat kernel version up to 6.4 and IBM Security Verify Governance, Identity Manager version up to ISVG 10.0.2.

4

Is CVE-2023-35825 still relevant?

No, CVE-2023-35825 is not relevant and should not be used; it is a duplicate of CVE-2023-3141.

5

What action should be taken regarding CVE-2023-35825?

Users should disregard CVE-2023-35825 and refer to CVE-2023-3141 for guidance and mitigation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203