CVE-2023-1990 is a use-after-free vulnerability in the Linux Kernel's NFC driver (ndlc_remove in drivers/nfc/st-nci/ndlc.c). This flaw, rated Medium severity (CVSS 4.7), allows a local, low-privileged attacker to crash the system due to a race condition, leading to a denial of service. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-1990
May 9, 2023A use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux Kernel. This flaw could allow an attacker to crash the system due to a race problem.
Apr 11, 2023kernel: Use after free bug in ndlc_remove due to race condition
Mar 15, 2023