A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attacker to guess the returned handle value and trigger a use-after-free issue, potentially leading to a denial of service or privilege escalation.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2023-11-09T19:15:47.605Z
Updated: 2024-11-15T17:03:59.899Z
Reserved: 2023-07-25T17:04:34.810Z
Link: CVE-2023-39198
Vulnrichment
Updated: 2024-08-02T18:02:05.368Z
NVD
Status : Modified
Published: 2023-11-09T20:15:08.730
Modified: 2024-09-13T19:15:13.593
Link: CVE-2023-39198
Redhat