CVE-2023-5178
high-risk
Published 2023-11-01
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
Do I need to act?
~
8.6% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
NETWORK
/ LOW complexity
Affected Products (6)
References (50)
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7370
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7379
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7418
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7548
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7549
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7551
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7554
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7557
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7559
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0340
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0378
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0386
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0412
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0431
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0432
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0461
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0554
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0575
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1268
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:1269
and 30 more references
53
/ 100
high-risk
Severity
30/34 · Critical
Exploitability
10/34 · Low
Exposure
13/34 · Low