CVE-2023-2007: Debian Linux

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only
  • Linux Linux Kernel: before 6.0 (fixed in 6.0)
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Netapp Solidfire & Hci Management Node: affected versions not specified

Published 2023-04-24. Last modified 2026-06-17.