VYPR
High severity7.8NVD Advisory· Published May 1, 2023· Updated Jun 17, 2026

CVE-2023-2236

CVE-2023-2236

Description

A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation.

Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability.

We recommend upgrading past commit 9d94c04c0db024922e886c9fd429659f22f48ea4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Linux/Kernelllm-fuzzy3 versions
    (expand)+ 2 more
    • (no CPE)
    • (no CPE)range: 5.19
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.19,<6.0.11
  • cpe:2.3:a:netapp:hci_baseboard_management_controller:h300s:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:netapp:hci_baseboard_management_controller:h300s:*:*:*:*:*:*:*
    • cpe:2.3:a:netapp:hci_baseboard_management_controller:h410c:*:*:*:*:*:*:*
    • cpe:2.3:a:netapp:hci_baseboard_management_controller:h410s:*:*:*:*:*:*:*
    • cpe:2.3:a:netapp:hci_baseboard_management_controller:h500s:*:*:*:*:*:*:*
    • cpe:2.3:a:netapp:hci_baseboard_management_controller:h700s:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.