CVE-2023-1872: Debian Linux

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation. The io_file_get_fixed function lacks the presence of ctx->uring_lock which can lead to a Use-After-Free vulnerability due a race condition with fixed files getting unregistered. We recommend upgrading past commit da24142b1ef9fd5d36b76e36bab328a5b27523e8.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 5.7, before 5.17 (fixed in 5.17)

Published 2023-04-12. Last modified 2026-06-17.