In the Linux kernel, the following vulnerability has been resolved:
vhost-vdpa: fix use after free in vhost_vdpa_probe()
The put_device() calls vhost_vdpa_release_dev() which calls
ida_simple_remove() and frees "v". So this call to
ida_simple_remove() is a use after free and a double free.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-05-21 16:15
Updated : 2025-01-10 17:59
NVD link : CVE-2023-52795
Mitre link : CVE-2023-52795
CVE.ORG link : CVE-2023-52795
JSON object : View
Products Affected
linux
- linux_kernel
