CVE-2023-2236: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.
Affected products
- Linux Linux Kernel: from 5.19, before 6.0.11 (fixed in 6.0.11)
- Netapp Hci Baseboard Management Controller: version h300s only; version h410c only; version h410s only; version h500s only; version h700s only
Published 2023-05-01. Last modified 2026-06-17.