VYPR
Medium severity4.7NVD Advisory· Published Jun 28, 2023· Updated Jun 17, 2026

CVE-2023-3439

CVE-2023-3439

Description

A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object, potentially leading to a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Linux/Kernel6 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.15,<=5.17
    • cpe:2.3:o:linux:linux_kernel:5.18:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:5.18:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:5.18:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:5.18:rc4:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.