A use-after-free vulnerability in... CVE-2023-2236

- AV AC AU C I A
发布: 2023-05-01
修订: 2023-08-11

A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.

0%
暂无可用Exp或PoC
当前有13条受影响产品信息