A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e
History

Wed, 14 Aug 2024 01:15:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2023-01-30T13:09:32.141Z

Updated: 2024-08-02T05:02:44.150Z

Reserved: 2023-01-13T07:58:13.390Z

Link: CVE-2023-0266

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-01-30T14:15:10.500

Modified: 2023-08-29T17:59:37.930

Link: CVE-2023-0266

cve-icon Redhat

Severity : Important

Publid Date: 2023-01-13T06:30:00Z

Links: CVE-2023-0266 - Bugzilla