• CVE-2023-47233

发布时间: 2024年4月26日

修改时间: 2024年4月26日

概要

The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unplugging (disconnect the USB by hotplug) code. For physically proximate attackers with local access, this "could be exploited in a real world scenario." This is related to brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.

CVSS v3 指标

NVD openEuler
CVSS评分 4.3 6.3
Attack Vector Physical Physical
Attack Complexity Low Low
Privileges Required Low High
User Interaction None None
Scope Unchanged Changed
Confidentiality None Low
Integrity None Low
Availability High High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4774 kernel security update 2024年4月26日

影响产品

产品 状态
KY3.4-4A kernel Fixed
KY3.4-5A kernel Fixed