CVE-2023-1476: Linux Kernel

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.

Affected products

  • Linux Linux Kernel: before 5.14 (fixed in 5.14)
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.8 only
  • Red Hat Enterprise Linux For Power Little Endian: version 8.0_ppc64le only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 8.8_ppc64le only
  • Red Hat Enterprise Linux Server Tus: version 8.8 only

Published 2023-11-03. Last modified 2026-06-17.