Use-After-Free Vulnerability in Linux Kernel's BRCM80211 Component
CVE-2023-47233

4.3MEDIUM

Key Information:

Vendor

Linux

Vendor
CVE Published:
3 November 2023

What is CVE-2023-47233?

The BRCM80211 component within the Linux kernel exhibits a use-after-free vulnerability in its code that handles device disconnection. This issue arises during the hotplugging process, specifically when the USB device is unplugged, leading to potential exploitation by physically proximate attackers with local access. The vulnerability is associated with the brcmf_cfg80211_escan_timeout_worker function and poses a significant security risk for affected systems running Linux kernel version 6.5.10 and earlier.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.