CVE-2023-0266: Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel
A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRVCTLIOCTLELEM{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e
Other sources
A use-after-free flaw was found in sndctlelemread in sound/core/control.c in Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. In this flaw a normal privileged, local attacker may impact the system due to a locking issue in the compat path, leading to a kernel information leak problem.
Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=56b88b50565cd8b946a2d00b0c83927b7ebb055e
— Red Hat
Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/Kernelto a version that resolves this vulnerability.Fixed in 6.2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.135-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux Kernelto a version that resolves this vulnerability.Patch 56b88b50565cd8b946a2d00b0c83927b7ebb055e
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0266?
CVE-2023-0266 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2023-0266?
To mitigate CVE-2023-0266, upgrade to Linux Kernel versions 6.2 or apply the appropriate patches provided in the latest updates.
Which systems are affected by CVE-2023-0266?
CVE-2023-0266 affects multiple versions of the Linux Kernel, particularly those between 4.14 and 6.1.6.
What is the type of vulnerability associated with CVE-2023-0266?
CVE-2023-0266 is a use-after-free vulnerability that arises from missing locks in the ALSA PCM package.
What can attackers achieve by exploiting CVE-2023-0266?
Exploitation of CVE-2023-0266 could allow attackers to gain ring0 access, leading to complete control of the affected system.