CVE-2023-6039

Updated: 2026-02-27 02:43:40.485538

Description:

A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb/lan78xx in the Linux Kernel. This flaw allows a local attacker to crash the system when the LAN78XX USB device detaches.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2023-11-21 04:11:41 This vulnerability is reachable only when a Microchip LAN78xx USB Ethernet adapter is attached to th...
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2023-11-20 04:07:49 Ignored due to low severity
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2023-11-20 04:07:49 Ignored due to low severity
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Not Vulnerable 2023-11-18 10:07:37
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Not Vulnerable 2023-11-18 10:07:38
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2023-11-20 04:07:49 Ignored due to low severity
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2023-11-20 04:07:49 Ignored due to low severity
Ubuntu 16.04 ELS linux-hwe 4.15.0 5.5 MEDIUM Ignored 2023-11-20 04:07:50 Ignored due to low severity
Ubuntu 16.04 ELS linux 4.4.0 5.5 MEDIUM Ignored 2023-11-20 04:07:50 Ignored due to low severity
Ubuntu 18.04 ELS linux 4.15.0 5.5 MEDIUM Ignored 2023-11-20 04:07:50 Ignored due to low severity