CVE-2023-2513

medium

Description

A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cause a system crash or other undefined behaviors.

References

https://lore.kernel.org/all/20220616021358.2504451-1-libaokun1%40huawei.com/

https://github.com/torvalds/linux/commit/67d7d8ad99be

https://bugzilla.redhat.com/show_bug.cgi?id=2193097

Details

Source: Mitre, NVD

Published: 2023-05-08

Updated: 2023-11-07

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:L/AC:L/Au:M/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 6.7

Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: Medium