CVE-2023-3141

Updated: 2023-11-07 19:21:52.090929

Description:

A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.1

Status

OS name Project name Version Score Severity Status Errata Last updated
AlmaLinux 9.2 ESU kernel 5.14.0 7.1 HIGH Needs Triage 2023-11-07 16:17:21
AlmaLinux 9.2 FIPS kernel 5.14.0 7.1 HIGH Needs Triage 2023-11-20 10:12:23
CentOS 6 ELS kernel 2.6.32 7.1 HIGH In Rollout CLSA-2023:1700591071 2023-11-21 16:16:38
CentOS 7 ELS kernel 3.10.0 7.1 HIGH Needs Triage 2023-09-18 17:12:43
CentOS 8.4 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2023:1693426883 2023-08-30 17:07:24
CentOS 8.5 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2023:1693424916 2023-08-30 17:07:24
CloudLinux 6 ELS kernel 2.6.32 7.1 HIGH In Testing 2023-09-22 09:31:39
Oracle Linux 6 ELS kernel 2.6.32 7.1 HIGH Released CLSA-2023:1700590262 2023-11-21 13:16:47
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.1 HIGH Released CLSA-2023:1689788960 2023-07-19 14:05:28
Ubuntu 16.04 ELS linux 4.4.0 7.1 HIGH Released CLSA-2023:1690395161 2023-07-26 17:06:12
Total: 11