CVE-2023-21400
MEDIUMAndroid - Kernel Memory Corruption due to Improper Locking in io_uring
Title source: llmDescription
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
References (9)
Core 9
Core References
Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSN-0098-1.html
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/07/14/2
Exploit, Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/07/19/2
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/07/19/7
Mailing List, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
Vendor Advisory
https://source.android.com/security/bulletin/pixel/2023-07-01
Third Party Advisory
https://www.debian.org/security/2023/dsa-5480
Vendor Advisory
https://security.netapp.com/advisory/ntap-20240119-0012/
Scores
CVSS v3
6.7
EPSS
0.0004
EPSS Percentile
12.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-667
Status
published
Products (3)
debian/debian_linux
10.0
debian/debian_linux
11.0
google/android
Published
Jul 13, 2023
Tracked Since
Feb 18, 2026