VulnerabilityModified
CVE-2023-21400
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking.
MEDIUM 6.7EPSS 0.26%
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-667
- Affected
- google/android · debian/debian linux
- Source
- security@android.com
References
- http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSN-0098-1.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2023/07/14/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/19/2Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/19/7Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/25/7Mailing List
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240119-0012/
- https://source.android.com/security/bulletin/pixel/2023-07-01Vendor Advisory
- https://www.debian.org/security/2023/dsa-5480Third Party Advisory
- http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSN-0098-1.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2023/07/14/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/19/2Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/19/7Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/25/7Mailing List
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240119-0012/
- https://source.android.com/security/bulletin/pixel/2023-07-01Vendor Advisory
- https://www.debian.org/security/2023/dsa-5480Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.