CVE-2023-21400

MEDIUM

Android - Kernel Memory Corruption due to Improper Locking in io_uring

Title source: llm
STIX 2.1

Description

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.

Scores

CVSS v3 6.7
EPSS 0.0004
EPSS Percentile 12.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-667
Status published
Products (3)
debian/debian_linux 10.0
debian/debian_linux 11.0
google/android
Published Jul 13, 2023
Tracked Since Feb 18, 2026