CVE-2023-5345
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2023-5345 is a local privilege escalation vulnerability affecting the Linux kernel's fs/smb/client component. This issue arises due to a use-after-free condition in the smb3_fs_context_parse_param function. Specifically, when an error occurs in this function, the password field in the ctx variable is freed but not set to NULL, resulting in a double free scenario. This vulnerability can be exploited by attackers to gain elevated privileges on the system. It's strongly advised to upgrade to past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705 to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
- Fedora Operating System
Affected Vendors
- LINUX
- Fedora Project