CVE-2023-1838: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a local attacker to crash the system, and could even lead to a kernel information leak problem.
Affected products
- Linux Linux Kernel: from 4.13, before 4.14.317 (fixed in 4.14.317); from 4.15, before 4.19.245 (fixed in 4.19.245); from 4.20, before 5.4.196 (fixed in 5.4.196); from 5.5, before 5.10.118 (fixed in 5.10.118); from 5.11, before 5.15.42 (fixed in 5.15.42); from 5.16, before 5.17.10 (fixed in 5.17.10)
- Netapp h300s: affected versions not specified
- Netapp h410c: affected versions not specified
- Netapp h410s: affected versions not specified
- Netapp h500s: affected versions not specified
- Netapp h700s: affected versions not specified
Published 2023-04-05. Last modified 2026-10-08.