« List of all CVEs

CVE-2023-5178

Kernel: use after free in nvmet_tcp_free_crypto in nvme

Published: 11/1/2023 Last updated: 11/6/2025 Reserved: 9/25/2023

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 8.8 High CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (27)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes orun rawlink rawlink-eio rawlink-lwt shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (53)

Product Vendor Version
Red Hat Enterprise Linux 7 Red Hat 12.2.3
Red Hat Enterprise Linux 8.2 Telecommunications Update Service Red Hat < unspecified
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat <= 1.1.9
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat n/a
Red Hat Enterprise Linux 6 Red Hat 15.2(7)E9
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat 4.66 64bit
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat < 2024.3.44799
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat < 4.8.04584.08
Red Hat Enterprise Linux 7 Red Hat 15.2(7)E10
Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat prior to version 15.3.064.17729
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat < 7.7.4
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat 15.2(7)E7
Red Hat Enterprise Linux 9 Red Hat n/a
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat 15.1(2)SY6
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat < 7.4.5
Red Hat Enterprise Linux 9 Red Hat < unspecified
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat < publication
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat < unspecified
Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat < 7.4.5
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat <= 1.0.1
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat All versions
Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat <= 1.0.3
Red Hat Enterprise Linux 6 Red Hat Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below
Red Hat Enterprise Linux 9 Red Hat 2019 (Core installation)
Red Hat Enterprise Linux 8.2 Telecommunications Update Service Red Hat < publication
Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat < unspecified
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat Aruba InstantOS 6.5.x: 6.5.4.23 and below
Red Hat Enterprise Linux 8 Red Hat prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x)
Red Hat Enterprise Linux 8.2 Telecommunications Update Service Red Hat 12.4(24)MDB4
Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat n/a
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat 8.5.3.0
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat 15.2(8)E
Red Hat Enterprise Linux 7 Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat < 4.8.4
Red Hat Enterprise Linux 9 Red Hat < 7.6.3
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat 6.3
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat < publication
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat < 7.6.3
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat 15.2(7b)E0b
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat < Genoa PI 1.0.0.C
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat n/a
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1
Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat 12.1.3
Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat < 7.7.4
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat n/a

References (100)