A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object, potentially leading to a denial of service.
[
{
"events": [
{
"introduced": "5.15"
},
{
"last_affected": "5.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.18-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.18-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.18-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.18-rc4"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-3439.json"