CVE-2023-3111: Use After Free
A use after free vulnerability was found in preparetorelocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfsioctlbalance() before calling btrfsioctldefrag().
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3111?
CVE-2023-3111 is classified as a use after free vulnerability, which can lead to potential arbitrary code execution.
How do I fix CVE-2023-3111?
To remediate CVE-2023-3111, users should upgrade to the latest patched version of the Linux Kernel, such as 5.10.223-1 or higher.
Which versions of the Linux Kernel are affected by CVE-2023-3111?
CVE-2023-3111 affects various versions of the Linux Kernel from 2.6.31 to 5.19.4.
What functionality is impacted by CVE-2023-3111?
CVE-2023-3111 can be triggered by calling btrfs_ioctl_balance() before btrfs_ioctl_defrag(), which may result in memory corruption.
Who is affected by CVE-2023-3111?
Users of the affected Linux Kernel versions, including those on Debian and various NetApp devices, are at risk from CVE-2023-3111.