A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb/lan78xx in the Linux Kernel. This flaw allows a local attacker to crash the system when the LAN78XX USB device detaches.
Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is to skip loading the affected module "lan78xx" onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~

History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-02-27T20:34:12.368Z

Reserved: 2023-11-08T19:23:55.857Z

Link: CVE-2023-6039

cve-icon Vulnrichment

Updated: 2024-08-02T08:21:17.266Z

cve-icon NVD

Status : Modified

Published: 2023-11-09T15:15:09.133

Modified: 2024-11-21T08:43:01.540

Link: CVE-2023-6039

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-07-26T06:30:00Z

Links: CVE-2023-6039 - Bugzilla

cve-icon OpenCVE Enrichment

No data.