CVE-2023-2236: Use-after-free in Linux kernel's Performance Events subsystem
A use-after-free vulnerability in the Linux Kernel iouring subsystem can be exploited to achieve local privilege escalation.
Both ioinstallfixedfile and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability.
We recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability with ID CVE-2023-2236?
CVE-2023-2236 is a use-after-free vulnerability in the Linux Kernel io_uring subsystem that can be exploited for local privilege escalation.
What software is affected by the CVE-2023-2236 vulnerability?
The Linux Kernel versions 5.19 to 6.1-rc6, and certain Netapp Hci Baseboard Management Controller models (h300s, h410c, h410s, h500s, h700s) are affected by the CVE-2023-2236 vulnerability.
What is the severity of CVE-2023-2236?
CVE-2023-2236 has a severity rating of high (7).
How can the CVE-2023-2236 vulnerability be exploited?
The CVE-2023-2236 vulnerability can be exploited through a use-after-free attack in the Linux Kernel io_uring subsystem, allowing an attacker to gain local privilege escalation.
What is the recommended action to mitigate CVE-2023-2236?
It is recommended to apply the patch provided by the Linux Kernel development team and Netapp for the affected software versions to mitigate the CVE-2023-2236 vulnerability.