← Back

CVE-2023-4387

nvd nist
Published: Aug 16, 2023Modified: Jun 3, 2025

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleaning up vmxnet3_rq_cleanup_all, which could also lead to a kernel information leak problem.

Affected (12)

1 product
Linux Kernel
1 product
Enterprise Linux
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 3.16.60 to 3.17
From 4.10 to 4.14.281
From 4.15 to 4.19.245
From 4.20 to 5.4.196
From 4.4 to 4.9.316
From 5.11 to 5.15.42
From 5.16 to 5.17.10
From 5.5 to 5.10.118
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 7.0
Version 8.0
Version 9.0

References (8)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.