CVE-2023-52654
MEDIUMLinux Kernel 5.4.220-5.4.263 - File Reference Cycle via io_uring Socket Transmission
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-52654. PoCs published by FoxyProxys.
AI-analyzed exploit summary This repository contains a Python-based privilege escalation exploit for CVE-2023-52654, targeting misconfigured setuid/setgid binaries, sudo permissions, and capabilities on Unix systems. It automates the escalation process by leveraging file read/write primitives and techniques like SSH key theft or cron manipulation.
Description
In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races with unix_stream_read_generic(). The safest fix would be to completely disallow sending io_uring files via sockets via SCM_RIGHT, so there are no possible cycles invloving registered files and thus rendering SCM accounting on the io_uring side unnecessary.
Exploits (1)
This repository contains a Python-based privilege escalation exploit for CVE-2023-52654, targeting misconfigured setuid/setgid binaries, sudo permissions, and capabilities on Unix systems. It automates the escalation process by leveraging file read/write primitives and techniques like SSH key theft or cron manipulation.
References (6)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H