TROYANOSYVIRUS
Volver a CVEs

CVE-2023-21400

MEDIUM
6.7

Descripcion

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.

Detalles CVE

Puntuacion CVSS v3.16.7
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioNONE
Publicado7/13/2023
Ultima modificacion2/13/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

debian:debian_linuxgoogle:android

Debilidades (CWE)

CWE-667

Referencias

http://www.openwall.com/lists/oss-security/2023/07/14/2(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2023/07/19/2(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2023/07/19/7(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2023/07/25/7(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20240119-0012/(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2023/dsa-5480(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.