CVE-2023-33288 is a use-after-free vulnerability in the bq24190_remove function of the Linux kernel, affecting versions prior to 6.2.9. This flaw could allow a local attacker to crash the system due to a race condition. Rated as Medium severity (CVSS 4.7), it requires low privileges and high attack complexity, with the primary impact being system availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.2.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-33288
Jun 13, 2023An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.
May 9, 2023kernel: use-after-free in bq24190_remove in drivers/power/supply/bq24190_charger.c
Mar 10, 2023