CVE-2023-1476: Linux Kernel
High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.
A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.
Affected products
- Linux Linux Kernel: before 5.14 (fixed in 5.14)
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Enterprise Linux Eus: version 8.8 only
- Red Hat Enterprise Linux For Power Little Endian: version 8.0_ppc64le only
- Red Hat Enterprise Linux For Power Little Endian Eus: version 8.8_ppc64le only
- Red Hat Enterprise Linux Server Tus: version 8.8 only
Published 2023-11-03. Last modified 2026-06-17.