Vulnerabilities > CVE-2023-2680 - Use After Free vulnerability in multiple products

047910
CVSS 8.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
qemu
redhat
CWE-416

Summary

This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750.

Vulnerable Configurations

Part Description Count
Application
Qemu
1
OS
Redhat
1

Common Weakness Enumeration (CWE)