CVE-2023-52445

Updated: 2025-08-20 01:48:58.957832

Description:

In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix use after free on context disconnection Upon module load, a kthread is created targeting the pvr2_context_thread_func function, which may call pvr2_context_destroy and thus call kfree() on the context object. However, that might happen before the usb hub_event handler is able to notify the driver. This patch adds a sanity check before the invalid read reported by syzbot, within the context disconnection call stack.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2025:1758796886 2025-09-25 18:15:31
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2024:1724774331 2024-09-09 12:27:35
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2024:1720468480 2024-07-23 17:23:50
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1711026398 2024-03-21 09:52:31
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1711026811 2024-03-21 09:52:32
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Already Fixed 2024-06-09 11:19:58
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Ignored 2025-01-10 22:44:12
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2024:1725187614 2024-09-01 12:25:39
RHEL 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2025:1750353839 2025-06-20 00:27:49
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Released CLSA-2024:1710946064 2024-03-20 11:09:32
Total: 12