NA

CVE-2023-23039

Published: 22/02/2023 Updated: 06/03/2023
CVSS v3 Base Score: 5.7 | Impact Score: 5.2 | Exploitability Score: 0.5
VMScore: 0

Vulnerability Summary

An issue exists in the Linux kernel up to and including 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 6.2.0

linux linux kernel

Vendor Advisories

Description<!---->A race condition leading to a use-after-free vulnerability was found in the Linux kernel's Sun Virtual Console Concentrator (VCC) This could result in a crash of the system or potential code execution if a physically proximate attacker removes a VCC device while calling open()A race condition leading to a use-after-free vulnerab ...