CVE-2023-0266: Linux Kernel Use-After-Free Vulnerability
High severity, CVSS 7.0. Actively exploited: in CISA KEV since 2023-03-30. EPSS: 3.7% chance of exploitation in the next 30 days.
A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e
Affected products
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: from 4.14, before 4.14.303 (fixed in 4.14.303); from 4.15, before 4.19.270 (fixed in 4.19.270); from 4.20, before 5.4.229 (fixed in 5.4.229); from 5.5, before 5.10.163 (fixed in 5.10.163); from 5.11, before 5.15.88 (fixed in 5.15.88); from 5.16, before 6.1.6 (fixed in 6.1.6)
Published 2023-01-30. Last modified 2026-06-17.