#VU75994 Use-after-free in Linux kernel - CVE-2023-2162
Published: May 10, 2023
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a use-after-free error within the scsi_sw_tcp_session_create() function in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux Kernel. A local user can trigger a use-after-free error and gain access to sensitive information.