
We found results for “”
CVE-2023-1032
Good to know:

Date: January 8, 2024
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c65c365350e056067.
Language: C
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Double Free
CWE-415Top Fix

Upgrade Version
Upgrade to version linux-yocto - 4.8.12+gitAUTOINC+926c93ae07_021b4aef55;linux-yocto - 4.10+gitAUTOINC+805ea440c7_b259a5d744;linux-libc-headers - 5.14
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | HIGH |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | LOW |
Availability (A): | HIGH |