CVE-2023-52656: io_uring: drop any code related to SCM_RIGHTS
In the Linux kernel, the following vulnerability has been resolved:
iouring: drop any code related to SCMRIGHTS
The Linux kernel CVE team has assigned CVE-2023-52656 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024051338-CVE-2023-52656-6545@gregkh/T
Other sources
In the Linux kernel, the following vulnerability has been resolved:
iouring: drop any code related to SCMRIGHTS
This is dead code after we dropped support for passing iouring fds over SCMRIGHTS, get rid of it.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.4.273 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.10.214 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.15.153 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.83 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.7.11 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52656?
CVE-2023-52656 is evaluated with a severity rating that indicates a potential risk to Linux kernel security.
How do I fix CVE-2023-52656?
To fix CVE-2023-52656, update your Linux kernel to the latest versions specified in the advisory.
What versions of the Linux kernel are affected by CVE-2023-52656?
CVE-2023-52656 affects specific kernel versions including those prior to 5.4.273, 5.10.214, 5.15.153, 6.1.83, and others.
Which distributions are impacted by CVE-2023-52656?
Debian and Red Hat distributions are among those impacted by CVE-2023-52656 due to their use of the affected kernel versions.
Is there a public exploit for CVE-2023-52656?
As of now, there is no widely known public exploit for CVE-2023-52656 reported by the cybersecurity community.