CVE-2023-21400
Summary
| CVE | CVE-2023-21400 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-13 00:15:00 UTC |
| Updated | 2024-01-19 16:15:00 UTC |
| Description | In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - Re: Our learnings from 42 Linux kernel exploits, we are limiting io_uring |
MISC |
www.openwall.com |
|
| [SECURITY] [DLA 3623-1] linux-5.10 security update |
MISC |
lists.debian.org |
|
| Debian -- Security Information -- DSA-5480-1 linux |
MISC |
www.debian.org |
|
| Pixel Update Bulletin—July 2023 | Android Open Source Project |
MISC |
source.android.com |
|
| oss-security - Re: Our learnings from 42 Linux kernel exploits, we
are limiting io_uring |
MISC |
www.openwall.com |
|
| CVE-2023-21400 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
|
security.netapp.com |
|
| Kernel Live Patch Security Notice LSN-0098-1 ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| oss-security - Re: Our learnings from 42 Linux kernel exploits, we
are limiting io_uring |
MISC |
www.openwall.com |
|
| oss-security - Re: Our learnings from 42 Linux kernel exploits, we
are limiting io_uring |
MISC |
www.openwall.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 6000212 Debian Security Update for linux (DSA 5480-1)
- 6000265 Debian Security Update for linux-5.10 (DLA 3623-1)
- 673406 EulerOS Security Update for kernel (EulerOS-SA-2023-3182)
- 673595 EulerOS Security Update for kernel (EulerOS-SA-2023-3247)
- 673692 EulerOS Security Update for kernel (EulerOS-SA-2023-3275)
- 754866 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3684-1)
- 754876 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3687-1)