In the Linux kernel, the following vulnerability has been resolved:
firewire: net: fix use after free in fwnetfinishincoming_packet()
The netif_rx() function frees the skb so we can't dereference it to save the skb->len.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53432.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53432.json"
[
{
"id": "CVE-2023-53432-286fb37f",
"target": {
"file": "drivers/firewire/net.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9040adc38cf6bfbb77034d558ac2c52f70d840ac",
"digest": {
"threshold": 0.9,
"line_hashes": [
"221859665296189254982206804088158381528",
"96815877624701915296926970017219679159",
"124768396190235414309022641630337859918",
"113865809973402519866904769680833945071",
"41119596512830073433190679790163235281",
"110925298893464609337333951738537241785",
"312897338177165888295111381962879773526",
"77042410173101646550852083122559167114",
"192900734872584484629054403252500109333",
"123441535161781791096097398722169840100",
"308712320477892148539425998687737226607",
"70312902870515548378956590435966199342",
"272535887641282601865474282451102768223",
"70779113586959573115637211691112156960",
"269262417833797140095791562078841889350"
]
},
"signature_type": "Line"
},
{
"id": "CVE-2023-53432-758a1c1a",
"target": {
"function": "fwnet_finish_incoming_packet",
"file": "drivers/firewire/net.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2ea70379e4f4efa95c9daa7f3f9bdd4d40aec927",
"digest": {
"function_hash": "200366973045821735611787288882404088226",
"length": 1479.0
},
"signature_type": "Function"
},
{
"id": "CVE-2023-53432-ba11d29e",
"target": {
"file": "drivers/firewire/net.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2ea70379e4f4efa95c9daa7f3f9bdd4d40aec927",
"digest": {
"threshold": 0.9,
"line_hashes": [
"221859665296189254982206804088158381528",
"96815877624701915296926970017219679159",
"124768396190235414309022641630337859918",
"113865809973402519866904769680833945071",
"41119596512830073433190679790163235281",
"110925298893464609337333951738537241785",
"312897338177165888295111381962879773526",
"77042410173101646550852083122559167114",
"192900734872584484629054403252500109333",
"123441535161781791096097398722169840100",
"308712320477892148539425998687737226607",
"70312902870515548378956590435966199342",
"272535887641282601865474282451102768223",
"70779113586959573115637211691112156960",
"269262417833797140095791562078841889350"
]
},
"signature_type": "Line"
},
{
"id": "CVE-2023-53432-bb8a8570",
"target": {
"function": "fwnet_finish_incoming_packet",
"file": "drivers/firewire/net.c"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9040adc38cf6bfbb77034d558ac2c52f70d840ac",
"digest": {
"function_hash": "200366973045821735611787288882404088226",
"length": 1479.0
},
"signature_type": "Function"
}
]