PT-2023-3408 · Linux+4 · Linux Kernel+4
Ruihan Li
·
Published
2023-06-27
·
Updated
2025-06-11
·
CVE-2023-3269
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 6.1 through 6.4
Description
A vulnerability exists in the memory management subsystem of the Linux kernel, related to incorrect lock handling for accessing and updating virtual memory areas (VMAs), leading to use-after-free problems. This issue can be exploited to execute arbitrary kernel code, escalate containers, and gain root privileges. The vulnerability is due to a locking bug in the virtual memory management subsystem that leads to a UAF-by-RCU vulnerability.
Recommendations
For Linux kernel versions 6.1 through 6.4, update to version 6.4.1, 6.3.11, or 6.1.37 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable virtual memory management subsystem to minimize the risk of exploitation. Avoid using the vulnerable
maple tree structure for managing virtual memory areas until the issue is resolved.Exploit
Fix
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu