CVE-2023-4134

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 416

Summary

CVE-2023-4134 is a use-after-free vulnerability identified in the cyttsp4_core driver of the Linux kernel. The issue arises in the device cleanup routine, wherein the watchdog_timer may be rearmed from the workqueue, leading to memory being accessed after it has been freed. This vulnerability can result in a local user causing a denial of service by crashing the system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share