CVE-2023-1476: Kpatch: mm/mremap.c: incomplete fix for cve-2022-41222
A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-1476?
CVE-2023-1476 is an incomplete fix for CVE-2022-41222, a use-after-free flaw in the Linux kernel's memory address space accounting code.
What is the severity of CVE-2023-1476?
The severity of CVE-2023-1476 is high with a CVSS severity score of 7.
How does CVE-2023-1476 impact the system?
CVE-2023-1476 can allow a local user to crash the system or potentially escalate their privileges.
Which software versions are affected by CVE-2023-1476?
Linux kernel versions up to and excluding 5.14, Redhat Enterprise Linux 8.0, Redhat Enterprise Linux Eus 8.8, Redhat Enterprise Linux For Power Little Endian 8.0_ppc64le, Redhat Enterprise Linux For Power Little Endian Eus 8.8_ppc64le, and Redhat Enterprise Linux Server Tus 8.8 are affected by CVE-2023-1476.
How can I fix CVE-2023-1476?
To fix CVE-2023-1476, update your Linux kernel to version 5.14 or apply the necessary patches provided by Redhat.