CVE-2023-2236 is a high-severity use-after-free vulnerability in the Linux Kernel's io_uring subsystem, specifically affecting Linux kernel versions and NetApp products utilizing it. This flaw, categorized as CWE-416, can lead to local privilege escalation due to a reference underflow when io_install_fixed_file or its callers invoke fput on an error. With a CVSS score of 7.8, it presents a low-complexity attack vector (AV:L/AC:L/PR:L) allowing an authenticated local attacker to achieve high confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable, and community discussion and media coverage are minimal. Organizations are advised to upgrade to a kernel version patched beyond commit 9d94c04c0db024922e886c9fd429659f22f48ea4 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.19, < 6.0.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
h300sCPE matchmatch criteria | cpe:2.3:a:netapp:hci_baseboard_management_controller:h300s:*:*:*:*:*:*:* | ||
h410cCPE matchmatch criteria | cpe:2.3:a:netapp:hci_baseboard_management_controller:h410c:*:*:*:*:*:*:* | ||
h410sCPE matchmatch criteria | cpe:2.3:a:netapp:hci_baseboard_management_controller:h410s:*:*:*:*:*:*:* | ||
h500sCPE matchmatch criteria | cpe:2.3:a:netapp:hci_baseboard_management_controller:h500s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.