CVE-2023-5178: Linux Kernel
High severity, CVSS 8.8. EPSS: 9.5% chance of exploitation in the next 30 days.
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
Affected products
- Linux Linux Kernel: from 5.0, before 5.4.260 (fixed in 5.4.260); from 5.5, before 5.10.199 (fixed in 5.10.199); from 5.11, before 5.15.137 (fixed in 5.15.137); from 5.16, before 6.1.60 (fixed in 6.1.60); from 6.2, before 6.5.9 (fixed in 6.5.9)
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Solidfire & Hci Management Node: affected versions not specified
- Netapp Solidfire & Hci Storage Node: affected versions not specified
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
Published 2023-11-01. Last modified 2026-06-17.