Description
A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This issue occurs when a user simultaneously calls DROPTAG ioctl and socket close happens, which could allow a local user to crash the system or potentially escalate their privileges on the system.
Related CPE's
o
linux
linux_kernel
2
References
Mailing ListPatchVendor Advisory
https://security.netapp.com/advisory/ntap-20230223-0005/
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 · High
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2023-01-12T19:15:24.327
1 year agoLast modified
2023-04-11T18:15:32.957
1 year ago