CVE Database
/

CVE-2023-52795

Back to search

CVE-2023-52795

Published: May 21, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix use after free in vhost_vdpa_probe() The put_device() calls vhost_vdpa_release_dev() which calls ida_simple_remove() and frees "v". So this call to ida_simple_remove() is a use after free and a double free.

VendorProductVersions

Linux

Linux

affected
ebe6a354fa7e0a7d5b581da31ad031b19d8693f9 - < c0f8b8fb7df9d1a38652eb5aa817afccd3c56111
affected
ebe6a354fa7e0a7d5b581da31ad031b19d8693f9 - < ae8ea4e200675a940c365b496ef8e3fb4123601c
affected
ebe6a354fa7e0a7d5b581da31ad031b19d8693f9 - < bf04132cd64ccde4e9e9765d489c83fe83c09b7f
affected
ebe6a354fa7e0a7d5b581da31ad031b19d8693f9 - < e07754e0a1ea2d63fb29574253d1fd7405607343

Linux

Linux

affected
6.0
unaffected
0 - < 6.0
unaffected
6.1.64 - <= 6.1.*
unaffected
6.5.13 - <= 6.5.*
unaffected
6.6.3 - <= 6.6.*

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now