CVE-2023-46862: Null Pointer Dereference
An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an iouring/fdinfo.c iouringshowfdinfo NULL pointer dereference can occur.
Other sources
Linux Kernel is vulnerable to a denial of service, caused by a NULL pointer dereference flaw in the iouringshowfdinfo function in iouring/fdinfo.c during a race with SQ thread exit. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Linux kernel issue?
The vulnerability ID is CVE-2023-46862.
What is the severity level of CVE-2023-46862?
CVE-2023-46862 has a severity level of medium.
What is the affected software?
The affected software is the Linux kernel version up to and including 6.5.9.
What is the Common Weakness Enumeration (CWE) for this vulnerability?
The CWE for CVE-2023-46862 is CWE-476.
Are there any references for further information on this vulnerability?
Yes, you can find more information on CVE-2023-46862 in the following references: [link 1](https://github.com/torvalds/linux/commit/7644b1a1c9a7ae8ab99175989bfc8676055edb46), [link 2](https://bugzilla.kernel.org/show_bug.cgi?id=218032#c4).