Executive Summary

Informations
Name CVE-2023-3439 First vendor Publication 2023-06-28
Vendor Cve Last vendor Modification 2023-07-06

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 4.7
Base Score 4.7 Environmental Score 4.7
impact SubScore 3.6 Temporal Score 4.7
Exploitabality Sub Score 1
 
Attack Vector Local Attack Complexity High
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object, potentially leading to a denial of service.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3439

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-416 Use After Free

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 7
Os 3473

Sources (Detail)

Source Url
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2217915
https://github.com/torvalds/linux/commit/b561275d633bcd8e0e8055ab86f1a13df75a...
MLIST http://www.openwall.com/lists/oss-security/2023/07/02/1

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
Date Informations
2024-03-12 13:38:41
  • Multiple Updates
2024-02-02 02:46:41
  • Multiple Updates
2024-02-01 12:30:23
  • Multiple Updates
2024-01-12 02:38:27
  • Multiple Updates
2023-12-29 02:35:52
  • Multiple Updates
2023-11-22 02:34:32
  • Multiple Updates
2023-09-29 13:28:40
  • Multiple Updates
2023-09-05 13:41:24
  • Multiple Updates
2023-09-05 01:29:30
  • Multiple Updates
2023-09-02 13:39:30
  • Multiple Updates
2023-09-02 01:29:57
  • Multiple Updates
2023-08-12 13:44:45
  • Multiple Updates
2023-08-12 01:29:11
  • Multiple Updates
2023-08-11 13:36:48
  • Multiple Updates
2023-08-11 01:30:04
  • Multiple Updates
2023-08-06 13:33:25
  • Multiple Updates
2023-08-06 01:28:49
  • Multiple Updates
2023-08-04 13:33:51
  • Multiple Updates
2023-08-04 01:29:13
  • Multiple Updates
2023-07-14 05:27:33
  • Multiple Updates
2023-07-14 01:28:45
  • Multiple Updates
2023-07-07 00:27:18
  • Multiple Updates
2023-07-02 21:27:21
  • Multiple Updates
2023-06-29 21:27:18
  • Multiple Updates
2023-06-29 00:27:19
  • First insertion