CVE-2023-2612: shiftfs lock unbalance in Ubuntu-specific kernels
Published May 30, 2023
·Updated
Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).
Affected Software
3 affected components
Ubuntu=20.04
Ubuntu=22.04
Ubuntu=22.10
Remediation
Event History
May 30, 2023
CVE Published
via MITRE·11:12 PM
Data Sourced
via MITRE·11:12 PM
DescriptionSeverityWeakness
May 31, 2023
Data Sourced
12:15 AM
Description
Jan 12, 2024
Data Sourced
via Debian·12:18 AM
DescriptionAffected Software
May 2, 2025
Data Sourced
via Ubuntu·02:11 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-2612?
CVE-2023-2612 has a severity rating that allows for local denial of service via a kernel deadlock.
2
How do I fix CVE-2023-2612?
To fix CVE-2023-2612, update your Ubuntu system to the latest kernel version provided by Canonical.
3
Which versions of Ubuntu are affected by CVE-2023-2612?
CVE-2023-2612 affects Ubuntu Linux versions 20.04, 22.04, and 22.10.
4
What is the nature of the vulnerability in CVE-2023-2612?
CVE-2023-2612 involves a race condition in the shiftfs file system related to inode locking.
5
Can CVE-2023-2612 be exploited remotely?
CVE-2023-2612 requires local access to exploit, making it less of a risk for remote attacks.