← Back to CVE List
Vulnerability Analysis
Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel

CVE-2023-0266

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e

CISA KEV
CVSS Base Score
7.9
HIGH
Exploitability:1.3
Impact Score:6.0
Temporal Score:-
EPSS:3.70%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2023-03-30
Ransomware Use
Unknown
KEV Due Date
2023-04-20
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
3.702%
EPSS Percentile
88.3th pct
GitHub Severity
HIGH
SSVC Exploitation
SSVC Automatable
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD