CVE-2023-1872

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
12/04/2023
Last modified:
13/02/2025

Description

A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation.<br /> <br /> The io_file_get_fixed function lacks the presence of ctx-&gt;uring_lock which can lead to a Use-After-Free vulnerability due a race condition with fixed files getting unregistered.<br /> <br /> We recommend upgrading past commit da24142b1ef9fd5d36b76e36bab328a5b27523e8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.7 (including) 5.17 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*