CVE-2023-2236
PoC ×2—CVSS 3.1
7.8 high
EPSS
<1%p36
Published
()
Modified
Description
A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.
In the news0 stories
No ingested article mentions this CVE yet.