Vulnerability Description
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | - | |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2023/07/14/2Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/19/2ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/19/7Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/25/7Mailing List
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20240119-0012/
- https://source.android.com/security/bulletin/pixel/2023-07-01Vendor Advisory
- https://www.debian.org/security/2023/dsa-5480Third Party Advisory
- http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2023/07/14/2Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/19/2ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/19/7Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/07/25/7Mailing List
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2023-21400?
CVE-2023-21400 is a vulnerability with a CVSS score of 6.7 (MEDIUM). In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privile...
How severe is CVE-2023-21400?
CVE-2023-21400 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-21400?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Debian Debian Linux.