CVE-2023-37454
use-after-free in udf_put_super and udf_close_lvid functions in fs/udf/super.c
References
Notes
carnil> There might be no upstream fix for it from upstream. As by
carnil> stated on the upstream thread about the issue: the reproducer
carnil> does modify the block device while the filesystem is mounted.
Bugs
Status
Branch |
Status |
4.19-buster-security |
needed
|
4.19-upstream-stable |
needed
|
5.10-bullseye-security |
needed
|
5.10-upstream-stable |
needed
|
6.1-bookworm-security |
needed
|
6.1-upstream-stable |
needed
|
6.6-upstream-stable |
unknown
|
6.8-upstream-stable |
unknown
|
sid |
needed
|
upstream |
needed
|