CVE-2023-0461: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not require any privilege. There is a use-after-free bug of icsk_ulp_data of a struct inet_connection_sock. When CONFIG_TLS is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable. The setsockopt TCP_ULP operation does not require any privilege. We recommend upgrading past commit 2c02d41d71f90a5168391b6a5f2954112ba2307c

Affected products

  • Linux Linux Kernel: from 4.13.0, before 4.14.303 (fixed in 4.14.303); from 4.19, before 4.19.270 (fixed in 4.19.270); from 5.4, before 5.4.229 (fixed in 5.4.229); from 5.10, before 5.10.163 (fixed in 5.10.163); from 5.15, before 5.15.88 (fixed in 5.15.88); from 6.0, before 6.0.19 (fixed in 6.0.19); …

Published 2023-02-28. Last modified 2026-06-17.