UBUNTU-CVE-2023-37454
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-37454
Summary:
Details: An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective about this.
References: https://ubuntu.com/security/CVE-2023-37454, https://syzkaller.appspot.com/bug?extid=61564e5023b7229ec85d, https://syzkaller.appspot.com/bug?extid=26873a72980f8fa8bc55, https://lore.kernel.org/all/[email protected]/T/, https://syzkaller.appspot.com/bug?extid=60864ed35b1073540d57, https://www.cve.org/CVERecord?id=CVE-2023-37454
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
