UBUNTU-CVE-2023-45898
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-45898
UBUNTU-CVE-2023-45898
Summary:
Details: The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
References: https://ubuntu.com/security/CVE-2023-45898, https://git.kernel.org/linus/768d612f79822d30a1e7d132a4d4b05337ce42ec, https://github.com/torvalds/linux/commit/768d612f79822d30a1e7d132a4d4b05337ce42ec, https://lore.kernel.org/lkml/[email protected]/T/, https://www.spinics.net/lists/stable-commits/msg317086.html, https://lkml.org/lkml/2023/8/13/477, https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.4, https://lore.kernel.org/lkml/CALcu4raD4h9coiyEBL4Bm0zjDwxC2CyPiTwsP3zFuhot6y9Beg@mail.gmail.com/, https://lore.kernel.org/all/[email protected]/, https://ubuntu.com/security/notices/USN-6536-1, https://ubuntu.com/security/notices/USN-6537-1, https://ubuntu.com/security/notices/USN-6573-1, https://www.cve.org/CVERecord?id=CVE-2023-45898
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
