7.0highHigh

CVE-2023-35823

Linux Linux Kernel

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.0 (v3.1)
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-362
Assigned by
cve@mitre.org

Dates

Published
2023-06-18
Last modified
2026-08-26
Sources
NVD

Affected products

  • Linux Linux Kernel4.15 - 4.19.283, 4.20 - 5.4.243, 5.5 - 5.10.180, 5.11 - 5.15.111, 5.16 - 6.1.28, 6.2 - 6.2.15, 6.3 - 6.3.2
  • Debian Debian Linux10.0

As listed in the NVD configuration data. Not a statement about your estate.

References