peter bassill · operator
$ cve CVE-2023-0266 JSON

CVE-2023-0266 KEV

7.9
HIGH · CVSS 3.1 · EPSS 3.7% (pctl 89)

Patch first

On CISA KEV — known exploited in the wild, due 2023-04-20.

Description

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e

Scoring

CVSS7.9 (HIGH, v3.1)
VectorCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H
EPSS3.7% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2023-04-20
Public exploitnone known
Published2023-01-30
Last modified2026-06-17

CISA KEV

NameLinux Kernel Use-After-Free Vulnerability
Added2023-03-30
Due2023-04-20
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (2)

VendorProduct
debiandebian linux
linuxlinux kernel

References

→ the Explorer  ·  watch your stack  ·  NVD