Tracker / CVE-2023-3389
CVE-2023-3389
High 7.8
A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We recommend upgrading past commit ef7dfac51d8ed961b742218f526bd589f3900a59 (4716c73b188566865bdd79c3a6709696a224ac04 for 5.10 stable and 0e388fce7aec40992eadee654193cad345d62663 for 5.15 stable).
Affected products and versions
| canonical | ubuntu_linux |
|---|---|
| debian | debian_linux |
| linux | linux_kernel · 5.10.162 → 5.10.185 |
| linux | linux_kernel · 5.13 → 6.4 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.