CVE-2023-4611: Linux Kernel

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.

Affected products

  • Linux Linux Kernel: from 6.4, before 6.4.8 (fixed in 6.4.8); version 6.5 only

Published 2023-08-29. Last modified 2026-09-11.