First published: Wed Jun 28 2023(Updated: )
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.
Credit: cve-coordination@google.com cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | >=5.6<=5.11 | |
Linux Linux kernel | >=5.6<5.10.162 | |
Linux Linux kernel | >=5.11<5.11.6 | |
Netapp H300s | ||
Netapp H410c | ||
Netapp H410s | ||
Netapp H500s | ||
Netapp H700s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1295 is a vulnerability that exists in the io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel versions 5.6 - 5.11, allowing a local user to elevate their privileges to root.
Linux kernel versions 5.6 - 5.11 are affected by CVE-2023-1295.
CVE-2023-1295 has a severity rating of high (7).
CVE-2023-1295 has been patched in the Linux kernel version 9eac1904d3364254d622b.
No, macOS versions such as Big Sur, Monterey, and Ventura are not affected by CVE-2023-1295.