Junglewise Threat Intelligence

CVE-2023-0266: Linux Kernel Use-After-Free Vulnerability

CVE-2023-0266 · Severity: critical · CVSS 7.9 · Exploited in the wild · Published 2023-03-30

Technologies: Linux Kernel, Debian Linux. Vendors: Linux, Debian.

Executive brief

A use-after-free vulnerability in the ALSA PCM package of the Linux Kernel occurs due to missing locks in SNDRV_CTL_IOCTL_ELEM_READ/WRITE32. This flaw allows a local system user to escalate privileges to ring0 access.

Affected products

  • Linux Linux Kernel up to (excluding) 6.2, 6.2 rc1
  • Debian Debian Linux 10.0

Timeline

  • 2023-03-30: disclosed
  • 2023-03-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-03-30: advisory
  • 2023-01-12: patched: Mainline kernel commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e

Related threats