Vulnerability Intelligence Report
Kernel: use after free in nvmet_tcp_free_crypto in nvme
CVE-2023-5178
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:9.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-416 ↗Use After Free
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.18.0-513.9.1.rt7.311.el8_9 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.18.0-513.9.1.el8_9 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8 | all |
| Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | 0:4.18.0-193.128.1.el8_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | 0:4.18.0-193.128.1.rt13.179.el8_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | 0:4.18.0-193.128.1.el8_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | 0:4.18.0-193.128.1.el8_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | all |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:4.18.0-305.114.1.el8_4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | 0:4.18.0-305.114.1.rt7.190.el8_4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | 0:4.18.0-305.114.1.el8_4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | 0:4.18.0-305.114.1.el8_4 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | all |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | all |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | 0:4.18.0-372.87.1.el8_6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | all |
| Red Hat | Red Hat Enterprise Linux 8.8 Extended Update Support | 0:4.18.0-477.43.1.el8_8 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | 0:5.14.0-362.18.1.el9_3 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9 | all |
| Red Hat | Red Hat Enterprise Linux 9 | 0:5.14.0-362.18.1.el9_3 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:5.14.0-70.85.1.el9_0 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 0:5.14.0-70.85.1.rt21.156.el9_0 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | all |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 0:5.14.0-284.40.1.el9_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | 0:5.14.0-284.40.1.rt14.325.el9_2 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 9.2 Extended Update Support | all |
| Red Hat | Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | 0:4.18.0-372.87.1.el8_6 < * (unaffected) |
| Red Hat | Red Hat Enterprise Linux 6 | all |
| Red Hat | Red Hat Enterprise Linux 7 | all |
| Red Hat | Red Hat Enterprise Linux 7 | all |
| Red Hat | Red Hat Enterprise Linux 9 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
9.141%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2023-09-25T16:38:10 |
| Published | 2023-11-01T16:32:20 |
| Patch Date | 2023-10-15 |
| Last Updated | 2026-03-24T11:22:55 |
Community Chatter & Buzz