PT-2022-6557 · Linux+2 · Linux Kernel+2

Published

2022-11-25

·

Updated

2023-09-05

·

CVE-2023-2236

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description A use-after-free vulnerability in the Linux Kernel io uring subsystem can be exploited to achieve local privilege escalation. Both io install fixed file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability.
Recommendations Upgrade past commit 9d94c04c0db024922e886c9fd429659f22f48ea4 to resolve the issue. As a temporary workaround, consider restricting access to the io uring subsystem until a patch is available.

Exploit

Fix

LPE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3364
ALT-PU-2022-3371
ALT-PU-2023-1023
ALT-PU-2023-1064
BDU:2023-02406
CVE-2023-2236

Affected Products

Alt Linux
Linux Kernel
Red Os