CVE-2023-54142 addresses a use-after-free vulnerability in the Linux kernel's GTP (GPRS Tunnelling Protocol) encapsulation module. This flaw, discovered by syzkaller, occurs because the 'release_sock()' function is incorrectly called after the socket's last reference count is released, leading to attempts to access freed memory. While specific affected products are not detailed beyond the Linux kernel, the issue impacts systems utilizing GTP. The severity of this vulnerability is moderate, with a FAUCET Risk Score of 7/100. A successful exploit could lead to system instability, denial of service, or potentially arbitrary code execution, though the attack vector and complexity are not explicitly defined. The vulnerability is not currently listed on the CISA KEV catalog, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite the lack of public exploits, the vulnerability has garnered significant community attention with 6 mentions and 6 media articles, primarily from SUSE security advisories detailing live patch updates for their Linux Enterprise products. This indicates active patching efforts by vendors, suggesting awareness of the potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.14.135, < 4.14.322CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.19.61, < 4.19.291CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.1.20, < 5.2CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.2.3, < 5.3CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.