CVE-2023-3389: Use after free in io_uring in the Linux Kernel
A use-after-free vulnerability in the Linux Kernel iouring subsystem can be exploited to achieve local privilege escalation.
Racing a iouring cancel poll request with a linked timeout can cause a UAF in a hrtimer.
We recommend upgrading past commit ef7dfac51d8ed961b742218f526bd589f3900a59 (4716c73b188566865bdd79c3a6709696a224ac04 for 5.10 stable and 0e388fce7aec40992eadee654193cad345d62663 for 5.15 stable).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.251-5Fixed in 6.1.170-3Fixed in 6.1.172-1Fixed in 6.12.86-1Fixed in 6.12.88-1Fixed in 7.0.7-1 - Upgrade
Upgrade
Linux Kernel io_uringto a version that resolves this vulnerability.Patch ef7dfac51d8ed961b742218f526bd589f3900a59 - Upgrade
Upgrade
Linux Kernel 5.10 stableto a version that resolves this vulnerability.Patch 4716c73b188566865bdd79c3a6709696a224ac04 - Upgrade
Upgrade
Linux Kernel 5.15 stableto a version that resolves this vulnerability.Patch 0e388fce7aec40992eadee654193cad345d62663
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3389?
CVE-2023-3389 has a high severity rating due to its potential for local privilege escalation.
How do I fix CVE-2023-3389?
To address CVE-2023-3389, upgrade your Linux kernel to a version that includes the security fixes, such as 5.10.223-1 or 6.12.12-1.
Which Linux distributions are affected by CVE-2023-3389?
CVE-2023-3389 affects several distributions including multiple versions of Ubuntu and Debian Linux.
What causes the vulnerability CVE-2023-3389?
CVE-2023-3389 is caused by a use-after-free condition in the Linux Kernel io_uring subsystem when racing cancel poll requests.
What versions of the Linux Kernel are vulnerable to CVE-2023-3389?
Versions from 5.10.162 to 5.10.185 and from 5.13 to 6.4 of the Linux Kernel are vulnerable to CVE-2023-3389.