CVE-2023-1652 is a use-after-free vulnerability in the NFS filesystem's nfsd4_ssc_setup_dul function within the Linux Kernel, affecting various Linux distributions including Red Hat Enterprise Linux. Rated 7.1 HIGH, a local attacker can exploit this with low complexity to cause a system crash or leak kernel information. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.14, < 5.15.91CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.2:rc1:*:*:*:*:*:* | ||
6.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.2:rc2:*:*:*:*:*:* | ||
6.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.2:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-1652
May 9, 2023A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.
Mar 14, 2023Kernel: use-after-free in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c
Jan 12, 2023