Description
A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb/lan78xx in the Linux Kernel. This flaw allows a local attacker to crash the system when the LAN78XX USB device detaches.
Published: 2023-11-09
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Mitigation for this issue is to skip loading the affected module "lan78xx" onto the system till we have a fix available, this can be done by a blacklist mechanism, this will ensure the driver is not loaded at the boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-58296 A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb/lan78xx in the Linux Kernel. This flaw allows a local attacker to crash the system when the LAN78XX USB device detaches.
Ubuntu USN Ubuntu USN USN-6534-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6534-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6534-3 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6626-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6626-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6626-3 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-6628-1 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-6628-2 Linux kernel (Intel IoTG) vulnerabilities
Ubuntu USN Ubuntu USN USN-6706-1 Linux kernel (OEM) vulnerability
History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Linux Linux Kernel
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-02-27T20:34:12.368Z

Reserved: 2023-11-08T19:23:55.857Z

Link: CVE-2023-6039

cve-icon Vulnrichment

Updated: 2024-08-02T08:21:17.266Z

cve-icon NVD

Status : Modified

Published: 2023-11-09T15:15:09.133

Modified: 2024-11-21T08:43:01.540

Link: CVE-2023-6039

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-07-26T06:30:00Z

Links: CVE-2023-6039 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses