UBUNTU-CVE-2023-5178
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-5178
UBUNTU-CVE-2023-5178
Summary:
Details: A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
References: https://ubuntu.com/security/CVE-2023-5178, https://git.kernel.org/linus/d920abd1e7c4884f9ecd0749d1921b7ab19ddfbd, https://www.openwall.com/lists/oss-security/2023/10/15/1, https://lore.kernel.org/linux-nvme/[email protected]/, https://ubuntu.com/security/notices/USN-6497-1, https://ubuntu.com/security/notices/USN-6534-1, https://ubuntu.com/security/notices/USN-6536-1, https://ubuntu.com/security/notices/USN-6537-1, https://ubuntu.com/security/notices/USN-6548-1, https://ubuntu.com/security/notices/USN-6549-1, https://ubuntu.com/security/notices/USN-6534-2, https://ubuntu.com/security/notices/USN-6549-2, https://ubuntu.com/security/notices/USN-6548-2, https://ubuntu.com/security/notices/USN-6534-3, https://ubuntu.com/security/notices/USN-6548-3, https://ubuntu.com/security/notices/USN-6549-3, https://ubuntu.com/security/notices/USN-6549-4, https://ubuntu.com/security/notices/USN-6573-1, https://ubuntu.com/security/notices/USN-6548-4, https://ubuntu.com/security/notices/USN-6548-5, https://ubuntu.com/security/notices/USN-6549-5, https://ubuntu.com/security/notices/USN-6635-1, https://www.cve.org/CVERecord?id=CVE-2023-5178
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
