CVE-2023-2612: Canonical Ubuntu Linux

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).

Affected products

  • Canonical Ubuntu Linux: version 20.04 only; version 22.04 only; version 22.10 only

Published 2023-05-31. Last modified 2026-06-17.