Skip to content

kernel CVE-2023-5345

Moderate
etungsten published GHSA-868r-x68r-5c5p Nov 13, 2023

Package

kernel-6.1 (bottlerocket)

Affected versions

<1.16.1

Patched versions

1.16.1

Description

A flaw was found in the SMB client component in the Linux kernel. In case of an error in smb3_fs_context_parse_param, ctx->password was freed, but the field was not set to NULL, potentially leading to a use-after-free vulnerability. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Severity

Moderate
4.7
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE ID

CVE-2023-5345

Weaknesses

No CWEs