A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash the system, and could even lead to a kernel information leak problem.
2023-04-05T19:15:07.793
2024-11-21T07:39:59.817
Modified
CVSSv3.1: 7.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 4.14.317 | Yes |
Operating System | linux | linux_kernel | < 4.19.245 | Yes |
Operating System | linux | linux_kernel | < 5.4.196 | Yes |
Operating System | linux | linux_kernel | < 5.10.118 | Yes |
Operating System | linux | linux_kernel | < 5.15.42 | Yes |
Operating System | linux | linux_kernel | < 5.17.10 | Yes |
Hardware | netapp | h300s | - | Yes |
Hardware | netapp | h410c | - | Yes |
Hardware | netapp | h410s | - | Yes |
Hardware | netapp | h500s | - | Yes |
Hardware | netapp | h700s | - | Yes |