CVE-2023-2612: Canonical Ubuntu Linux
Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).
Affected products
- Canonical Ubuntu Linux: version 20.04 only; version 22.04 only; version 22.10 only
Published 2023-05-31. Last modified 2026-06-17.