Bug 7054 - BUG: CVE-2023-28464.
Summary: BUG: CVE-2023-28464.
Status: RESOLVED WONTFIX
Alias: None
Product: ANCK 5.10 Dev
Classification: ANCK
Component: drivers (show other bugs) drivers
Version: 5.10.y-15
Hardware: All Linux
: P3-Medium S3-normal
Target Milestone: ---
Assignee: GuixinLiu
QA Contact: shuming
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-10-24 16:55 UTC by ljubomir
Modified: 2023-10-24 17:09 UTC (History)
2 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description ljubomir inspur_group 2023-10-24 16:55:22 UTC
Description of problem:
A double-free vulnerability was found in the hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux Kernel. This issue may cause a denial of service or privilege escalation.
Comment 1 GuixinLiu alibaba_cloud_group 2023-10-24 17:03:28 UTC
CVE center 显示 4.19 和 5.10 都是not affected,不修复。
https://cve-center.openanolis.cn/official/detail?cve_id=CVE-2023-28464
Comment 2 小龙 admin 2023-10-24 17:09:14 UTC
The PR Link: https://gitee.com/anolis/cloud-kernel/pulls/2361