CVE-2023-1838: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash the system, and could even lead to a kernel information leak problem.

Affected products

  • Linux Linux Kernel: from 4.13, before 4.14.317 (fixed in 4.14.317); from 4.15, before 4.19.245 (fixed in 4.19.245); from 4.20, before 5.4.196 (fixed in 5.4.196); from 5.5, before 5.10.118 (fixed in 5.10.118); from 5.11, before 5.15.42 (fixed in 5.15.42); from 5.16, before 5.17.10 (fixed in 5.17.10)
  • Netapp h300s: affected versions not specified
  • Netapp h410c: affected versions not specified
  • Netapp h410s: affected versions not specified
  • Netapp h500s: affected versions not specified
  • Netapp h700s: affected versions not specified

Published 2023-04-05. Last modified 2026-10-08.