CVE-2023-3141

Updated: 2025-03-11 22:08:54.51048

Description:

A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.1 HIGH Released CLSA-2024:1712263970 2024-04-07 09:57:10
AlmaLinux 9.2 FIPS kernel 5.14.0 7.1 HIGH Released CLSA-2024:1712570434 2024-04-08 10:43:39
CentOS 6 ELS kernel 2.6.32 7.1 HIGH Released CLSA-2023:1700591071 2023-12-05 13:15:47
CentOS 7 ELS kernel 3.10.0 7.1 HIGH Released CLSA-2024:1720468480 2024-07-23 17:31:58
CentOS 8.4 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2023:1693426883 2023-08-30 17:07:24
CentOS 8.5 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2023:1693424916 2023-08-30 17:07:24
CentOS Stream 8 ELS kernel 4.18.0 7.1 HIGH Already Fixed 2024-06-29 10:08:37
CloudLinux 6 ELS kernel 2.6.32 7.1 HIGH Ignored 2025-01-10 22:44:18
CloudLinux 7 ELS kernel 3.10.0 7.1 HIGH Ignored 2025-01-22 01:36:15
Oracle Linux 6 ELS kernel 2.6.32 7.1 HIGH Released CLSA-2023:1700590262 2023-11-21 13:16:47
Total: 13