CVE-2023-2006: Linux Kernel RxRPC Race Condition Privilege Escalation Vulnerability
A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.
Other sources
A race condition was found in the Linux kernel's RxRPC network protocol. Quoting ZDI security advisory [1]:
"This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the processing of RxRPC bundles. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the kernel."
[1] https://www.zerodayinitiative.com/advisories/ZDI-23-439/
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-2006?
CVE-2023-2006 is a privilege escalation vulnerability in the Linux Kernel.
How severe is CVE-2023-2006?
CVE-2023-2006 has a severity score of 8.8 out of 10.
Who is affected by CVE-2023-2006?
Linux Kernel versions 5.10.0 to 5.10.157, 5.11.0 to 5.15.81, and 5.16.0 to 6.0.11 are affected by CVE-2023-2006.
What is the impact of CVE-2023-2006?
CVE-2023-2006 allows local attackers to escalate privileges on affected installations of Linux Kernel.
How can CVE-2023-2006 be fixed?
Updating to Linux Kernel version 6.1 or applying the necessary security patches from Red Hat resolves CVE-2023-2006.