A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation.
The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free.
We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.
The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free.
We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-3623-1 | linux-5.10 security update |
![]() |
DLA-3710-1 | linux security update |
![]() |
DSA-5492-1 | linux security update |
![]() |
EUVD-2023-54475 | A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free. We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c. |
![]() |
USN-6415-1 | Linux kernel (OEM) vulnerabilities |
![]() |
USN-6439-1 | Linux kernel vulnerabilities |
![]() |
USN-6439-2 | Linux kernel (AWS) vulnerabilities |
![]() |
USN-6440-1 | Linux kernel vulnerabilities |
![]() |
USN-6440-2 | Linux kernel (Azure) vulnerabilities |
![]() |
USN-6440-3 | Linux kernel (HWE) vulnerabilities |
![]() |
USN-6441-1 | Linux kernel vulnerabilities |
![]() |
USN-6441-2 | Linux kernel (GCP) vulnerabilities |
![]() |
USN-6441-3 | Linux kernel vulnerabilities |
![]() |
USN-6442-1 | Linux kernel (BlueField) vulnerabilities |
![]() |
USN-6444-1 | Linux kernel vulnerabilities |
![]() |
USN-6444-2 | Linux kernel (StarFive) vulnerabilities |
![]() |
USN-6445-1 | Linux kernel (Intel IoTG) vulnerabilities |
![]() |
USN-6445-2 | Linux kernel (Intel IoTG) vulnerabilities |
![]() |
USN-6446-1 | Linux kernel vulnerabilities |
![]() |
USN-6446-2 | Linux kernel vulnerabilities |
![]() |
USN-6446-3 | Linux kernel (Oracle) vulnerabilities |
![]() |
USN-6466-1 | Linux kernel (NVIDIA) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Feb 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free. We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c. | A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free. We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c. |
Tue, 13 Aug 2024 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/o:redhat:rhel_aus:7.7 |

Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-02-13T17:14:20.913Z
Reserved: 2023-08-30T11:57:48.389Z
Link: CVE-2023-4622

No data.

Status : Modified
Published: 2023-09-06T14:15:12.193
Modified: 2025-02-13T18:15:46.213
Link: CVE-2023-4622


No data.