Skip to content

kernel CVE-2023-28466

High
cbgbt published GHSA-9fh9-wqhq-6x64 May 12, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.14.0

Patched versions

1.14.0
kernel-5.15 (bottlerocket)
< 1.14.0
1.14.0

Description

A use-after-free flaw was found in the Transport Layer Security (TLS) implementation in the Linux kernel. This flaw can cause a NULL pointer dereference problem due to a race condition.

Severity

High

CVE ID

CVE-2023-28466

Weaknesses

No CWEs