CVE-2023-21400: Medium severity android vulnerability
Published Jul 12, 2023
·Updated
In multiple functions of iouring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
Affected Software
4 affected componentsFixes available
Google Android
Debian Linux=10.0
Debian Linux=11.0
debian/linux
5.10.223-15.10.234-16.1.137-16.1.135-16.12.27-1
Remediation
Event History
Jul 12, 2023
CVE Published
via MITRE·11:53 PM
Data Sourced
via MITRE·11:53 PM
DescriptionWeakness
Jan 28, 2024
Data Sourced
via Launchpad·12:20 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·02:10 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-21400?
CVE-2023-21400 is a vulnerability in multiple functions of io_uring.c that could lead to local escalation of privilege in the kernel.
2
What is the severity of CVE-2023-21400?
The severity of CVE-2023-21400 is medium with a CVSS score of 6.7.
3
How can CVE-2023-21400 be exploited?
CVE-2023-21400 can be exploited without user interaction.
4
Which software versions are affected by CVE-2023-21400?
The affected software versions include Linux versions 5.18.2-1, 5.15.0-82.91, and others.
5
Where can I find more information about CVE-2023-21400?
You can find more information about CVE-2023-21400 on the official Google Android security bulletin and openwall.com.