CVE-2023-52846

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-52846
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52846.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-52846
Downstream
Related
Published
2024-05-21T15:31:43.863Z
Modified
2025-11-28T02:34:19.168365Z
Summary
hsr: Prevent use after free in prp_create_tagged_frame()
Details

In the Linux kernel, the following vulnerability has been resolved:

hsr: Prevent use after free in prpcreatetagged_frame()

The prpfillrct() function can fail. In that situation, it frees the skb and returns NULL. Meanwhile on the success path, it returns the original skb. So it's straight forward to fix bug by using the returned value.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52846.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
451d8123f89791bb628277c0bdb4cae34a3563e6
Fixed
ddf4e04e946aaa6c458b8b6829617cc44af2bffd
Fixed
a1a485e45d24b1cd8fe834fd6f1b06e2903827da
Fixed
6086258bd5ea7b5c706ff62da42b8e271b2401db
Fixed
1787b9f0729d318d67cf7c5a95f0c3dba9a7cc18
Fixed
d103fb6726904e353b4773188ee3d3acb4078363
Fixed
876f8ab52363f649bcc74072157dfd7adfbabc0d

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.9.0
Fixed
5.10.201
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.139
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.63
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.5.12
Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.6.2