---
id: CVE-2023-1118
title: >-
  A flaw use after free in the Linux kernel integrated infrared
  receiver/transceiver driver was found in the way user detaching rc device
summary: >-
  A flaw use after free in the Linux kernel integrated infrared
  receiver/transceiver driver was found in the way user detaching rc device. A
  local user could use this flaw to crash the system or potentially escalate
  their privileges on the…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: adp
cwe:
  - CWE-416
product: Kernel
affected:
  - Kernel Linux kernel 6.3-rc1
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-04-23T13:28:55.993598Z'
published: '2023-03-02'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:02:51.571Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2023-1118'
references:
  - url: >-
      https://github.com/torvalds/linux/commit/29b0589a865b6f66d141d79b2dd1373e4e50fe17
  - url: 'https://security.netapp.com/advisory/ntap-20230413-0003/'
  - url: 'https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html'
    label: >-
      [debian-lts-announce] 20230502 [SECURITY] [DLA 3404-1] linux-5.10 security
      update
  - url: 'https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html'
    label: >-
      [debian-lts-announce] 20230503 [SECURITY] [DLA 3403-1] linux security
      update
tags:
  - cve.org
epss: 0.0028
epssPercentile: 0.18219
ingestedAt: '2026-09-18T01:33:24.272Z'
---

## Overview

A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

## Affected

- `Kernel Linux kernel 6.3-rc1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
