CVE-2023-23586

CVSS v3.1 5.5 (Medium)
55% Progress
EPSS 0.04 % (13th)
0.04% Progress
Affected Products 1
Advisories 3

Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process. timens_install calls current_is_single_threaded to determine if the current process is single-threaded, but this call does not consider io_uring's io_worker threads, thus it is possible to insert a time namespace's vvar page to process's memory space via a page fault. When this time namespace is destroyed, the vvar page is also freed, but not removed from the process' memory, and a next page allocated by the kernel will be still available from the user-space process and can leak memory contents via this (read-only) use-after-free vulnerability. We recommend upgrading past version 5.10.161 or commit  788d0824269bef539fe31a785b1517882eafed93 https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/io_uring

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Google Inc.
Published Date
2023-02-17 13:15:10
(19 months ago)
Updated Date
2023-11-07 04:07:47
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 5.6 version and prior 5.10.161 version cpe:2.3:o:linux:linux_kernel >= 5.6 < 5.10.161
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...