Executive brief
A use-after-free vulnerability in the ALSA PCM package of the Linux Kernel occurs due to missing locks in SNDRV_CTL_IOCTL_ELEM_READ/WRITE32. This flaw allows a local system user to escalate privileges to ring0 access.
Affected products
- Linux Linux Kernel up to (excluding) 6.2, 6.2 rc1
- Debian Debian Linux 10.0
Timeline
- 2023-03-30: disclosed
- 2023-03-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-03-30: advisory
- 2023-01-12: patched: Mainline kernel commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e