CVE-2023-47233 is a use-after-free vulnerability in the brcm80211 component of the Linux kernel, affecting versions up to 6.5.10. This flaw, specifically in the brcmf_cfg80211_detach function during device unplugging, could lead to a denial of service. With a CVSS score of 4.3 (Medium), exploitation requires physical proximity and local access, indicating a low attack complexity but a high impact on availability. While the vulnerability is considered exploitable in real-world scenarios, there is currently no public exploit code available, and it is not listed on the CISA KEV catalog. Community discussion and media coverage are minimal, suggesting limited active attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.5.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Certain HP Enterprise LaserJet, HP LaserJet Managed Printers – Potential Denial of Service
Sep 11, 2024Certain HP Enterprise LaserJet, HP LaserJet Managed Printers – Potential Denial of Service
Sep 11, 2024The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unplugging (disconnect the USB by hotplug) code. For physically proximate attackers with local access this "could be exploited in a real world scenario." This is related to brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.
Nov 14, 2023kernel: Use after free in brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c
Nov 3, 2023