High severity8.1NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026
CVE-2023-3297
CVE-2023-3297
Description
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:a:canonical:accountsservice:*:*:*:*:*:*:*:*Range: <23.13.9-2ubuntu2
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:22.10:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*
- Canonical Ltd./AccountServicev5Range: 23.13.9-2ubuntu2
Patches
Vulnerability mechanics
References
4- bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2024182nvdExploitIssue TrackingVendor Advisory
- securitylab.github.com/advisories/GHSL-2023-139_accountsservice/nvdExploitThird Party Advisory
- cve.mitre.org/cgi-bin/cvename.cginvdThird Party Advisory
- ubuntu.com/security/notices/USN-6190-1nvdVendor Advisory
News mentions
0No linked articles in our index yet.