UBUNTU-CVE-2023-47233
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-47233
UBUNTU-CVE-2023-47233
Summary:
Details: The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unplugging (disconnect the USB by hotplug) code. For physically proximate attackers with local access, this "could be exploited in a real world scenario." This is related to brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.
References: https://ubuntu.com/security/CVE-2023-47233, https://lore.kernel.org/all/[email protected]/, https://marc.info/?l=linux-kernel&m=169907678011243&w=2, https://www.cve.org/CVERecord?id=CVE-2023-47233, https://ubuntu.com/security/notices/USN-6774-1, https://ubuntu.com/security/notices/USN-6775-1, https://ubuntu.com/security/notices/USN-6776-1, https://ubuntu.com/security/notices/USN-6777-1, https://ubuntu.com/security/notices/USN-6778-1, https://ubuntu.com/security/notices/USN-6777-2, https://ubuntu.com/security/notices/USN-6775-2, https://ubuntu.com/security/notices/USN-6777-3, https://ubuntu.com/security/notices/USN-6777-4, https://ubuntu.com/security/notices/USN-6795-1, https://ubuntu.com/security/notices/USN-6816-1, https://ubuntu.com/security/notices/USN-6817-1, https://ubuntu.com/security/notices/USN-6817-2, https://ubuntu.com/security/notices/USN-6828-1, https://ubuntu.com/security/notices/USN-6817-3, https://ubuntu.com/security/notices/USN-6878-1
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
