CVE-2023-35825: Use After Free
REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-3141. Reason: This candidate is a reservation duplicate of CVE-2023-3141. Notes: All CVE users should reference CVE-2023-3141 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Other sources
An issue was discovered in the Linux kernel before 6.3.4. A use-after-free was found in r592remove in drivers/memstick/host/r592.c.
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=63264422785021704c39b38f65a78ab9e4a186d7 https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.4 https://lore.kernel.org/lkml/20230501030540.3254928-4-sashal@kernel.org/ https://lore.kernel.org/all/20230523164950.435226211@linuxfoundation.org/
— Red Hat
Linux Kernel could allow a local authenticated attacker to execute arbitrary code on the system, caused by a use-after-free flaw in the r592remove function in drivers/memstick/host/r592.c. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35825?
CVE-2023-35825 is marked as a duplicate and does not have a severity rating since it should be referenced to CVE-2023-3141.
How do I fix CVE-2023-35825?
Since CVE-2023-35825 is a duplicate, fixes should be sought in the patches or updates related to CVE-2023-3141.
Which software is affected by CVE-2023-35825?
CVE-2023-35825 affects Red Hat kernel version up to 6.4 and IBM Security Verify Governance, Identity Manager version up to ISVG 10.0.2.
Is CVE-2023-35825 still relevant?
No, CVE-2023-35825 is not relevant and should not be used; it is a duplicate of CVE-2023-3141.
What action should be taken regarding CVE-2023-35825?
Users should disregard CVE-2023-35825 and refer to CVE-2023-3141 for guidance and mitigation.