{"id":"UBUNTU-CVE-2023-23039","details":"An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().","modified":"2025-08-28T17:07:18Z","published":"2023-02-22T17:15:00Z","withdrawn":"2025-09-03T17:41:58Z","upstream":["CVE-2023-23039"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-23039"},{"type":"REPORT","url":"https://lore.kernel.org/lkml/20230102010528.2868403-1-yoochan1026@gmail.com/"},{"type":"REPORT","url":"https://lkml.org/lkml/2023/1/1/169"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-23039"}],"affected":[{"package":{"name":"linux","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/linux@4.4.0-272.306?arch=source&distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.2.0-16.19","4.2.0-17.21","4.2.0-19.23","4.3.0-1.10","4.3.0-2.11","4.3.0-5.16","4.3.0-6.17","4.3.0-7.18","4.4.0-2.16","4.4.0-4.19","4.4.0-6.21","4.4.0-7.22","4.4.0-8.23","4.4.0-9.24","4.4.0-10.25","4.4.0-11.26","4.4.0-12.28","4.4.0-13.29","4.4.0-14.30","4.4.0-15.31","4.4.0-16.32","4.4.0-17.33","4.4.0-18.34","4.4.0-21.37","4.4.0-22.39","4.4.0-22.40","4.4.0-24.43","4.4.0-28.47","4.4.0-31.50","4.4.0-34.53","4.4.0-36.55","4.4.0-38.57","4.4.0-42.62","4.4.0-43.63","4.4.0-45.66","4.4.0-47.68","4.4.0-51.72","4.4.0-53.74","4.4.0-57.78","4.4.0-59.80","4.4.0-62.83","4.4.0-63.84","4.4.0-64.85","4.4.0-65.86","4.4.0-66.87","4.4.0-67.88","4.4.0-70.91","4.4.0-71.92","4.4.0-72.93","4.4.0-75.96","4.4.0-77.98","4.4.0-78.99","4.4.0-79.100","4.4.0-81.104","4.4.0-83.106","4.4.0-87.110","4.4.0-89.112","4.4.0-91.114","4.4.0-92.115","4.4.0-93.116","4.4.0-96.119","4.4.0-97.120","4.4.0-98.121","4.4.0-101.124","4.4.0-103.126","4.4.0-104.127","4.4.0-108.131","4.4.0-109.132","4.4.0-112.135","4.4.0-116.140","4.4.0-119.143","4.4.0-121.145","4.4.0-122.146","4.4.0-124.148","4.4.0-127.153","4.4.0-128.154","4.4.0-130.156","4.4.0-131.157","4.4.0-133.159","4.4.0-134.160","4.4.0-135.161","4.4.0-137.163","4.4.0-138.164","4.4.0-139.165","4.4.0-140.166","4.4.0-141.167","4.4.0-142.168","4.4.0-143.169","4.4.0-145.171","4.4.0-146.172","4.4.0-148.174","4.4.0-150.176","4.4.0-151.178","4.4.0-154.181","4.4.0-157.185","4.4.0-159.187","4.4.0-161.189","4.4.0-164.192","4.4.0-165.193","4.4.0-166.195","4.4.0-168.197","4.4.0-169.198","4.4.0-170.199","4.4.0-171.200","4.4.0-173.203","4.4.0-174.204","4.4.0-176.206","4.4.0-177.207","4.4.0-178.208","4.4.0-179.209","4.4.0-184.214","4.4.0-185.215","4.4.0-186.216","4.4.0-187.217","4.4.0-189.219","4.4.0-190.220","4.4.0-193.224","4.4.0-194.226","4.4.0-197.229","4.4.0-198.230","4.4.0-200.232","4.4.0-201.233","4.4.0-203.235","4.4.0-204.236","4.4.0-206.238","4.4.0-208.240","4.4.0-209.241","4.4.0-210.242","4.4.0-211.243","4.4.0-212.244","4.4.0-213.245","4.4.0-214.246","4.4.0-216.249","4.4.0-217.250","4.4.0-218.251","4.4.0-219.252","4.4.0-221.254","4.4.0-222.255","4.4.0-223.256","4.4.0-224.257","4.4.0-227.261","4.4.0-229.263","4.4.0-230.264","4.4.0-231.265","4.4.0-233.267","4.4.0-234.268","4.4.0-235.269","4.4.0-236.270","4.4.0-237.271","4.4.0-239.273","4.4.0-240.274","4.4.0-241.275","4.4.0-242.276","4.4.0-243.277","4.4.0-244.278","4.4.0-245.279","4.4.0-246.280","4.4.0-248.282","4.4.0-250.284","4.4.0-251.285","4.4.0-252.286","4.4.0-253.287","4.4.0-254.288","4.4.0-256.290","4.4.0-257.291","4.4.0-258.292","4.4.0-259.293","4.4.0-260.294","4.4.0-261.295","4.4.0-262.296","4.4.0-263.297","4.4.0-264.298","4.4.0-266.300","4.4.0-267.301","4.4.0-268.302","4.4.0-269.303","4.4.0-270.304","4.4.0-271.305","4.4.0-272.306"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-23039.json"}},{"package":{"name":"linux-raspi2","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/linux-raspi2@5.4.0-1006.6?arch=source&distro=esm-infra/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.3.0-1007.8","5.3.0-1014.16","5.3.0-1015.17","5.3.0-1017.19","5.4.0-1004.4","5.4.0-1006.6"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-23039.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"negligible"}]}