CVE-2023-2612: shiftfs lock unbalance in Ubuntu-specific kernels

Published May 30, 2023
·
Updated

Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).

Affected Software

3 affected components
Ubuntu=20.04
Ubuntu=22.04
Ubuntu=22.10

Event History

May 30, 2023
CVE Published
via MITRE·11:12 PM
Data Sourced
via MITRE·11:12 PM
DescriptionSeverityWeakness
May 31, 2023
Data Sourced
12:15 AM
Description
Jan 12, 2024
Data Sourced
via Debian·12:18 AM
DescriptionAffected Software
May 2, 2025
Data Sourced
via Ubuntu·02:11 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-2612?

CVE-2023-2612 has a severity rating that allows for local denial of service via a kernel deadlock.

2

How do I fix CVE-2023-2612?

To fix CVE-2023-2612, update your Ubuntu system to the latest kernel version provided by Canonical.

3

Which versions of Ubuntu are affected by CVE-2023-2612?

CVE-2023-2612 affects Ubuntu Linux versions 20.04, 22.04, and 22.10.

4

What is the nature of the vulnerability in CVE-2023-2612?

CVE-2023-2612 involves a race condition in the shiftfs file system related to inode locking.

5

Can CVE-2023-2612 be exploited remotely?

CVE-2023-2612 requires local access to exploit, making it less of a risk for remote attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203