Database/Kernel, userspace & hypervisor
Linux kernel (io_uring): Use-after-free between io_uring and the unix GC - local root
CVSS 7.0CVE-2022-2602Kernel, userspace & hypervisorcurated
Impact
Use-after-free between io_uring and the unix GC - local root
Who can reach it
Any tenant process in a container with io_uring enabled
What to do
Livepatchable; otherwise drain + reboot. Durable control: block io_uring via seccomp in the default container profile
References
Related entries
- Linux kernel (io_uring): io_uring fixed-buffer registration gives out-of-bounds access to physical memoryCVE-2023-2598 · Linux kernel (io_uring)High
- Linux kernel (io_uring): Page use-after-free via io_uring buffer-ring mmap - unprivileged local user to rootCVE-2024-0582 · Linux kernel (io_uring)High
- Linux kernel (OverlayFS/FUSE): OverlayFS copies setuid files from a nosuid FUSE mountCVE-2023-0386 · Linux kernel (OverlayFS/FUSE)High
- Linux kernel (arch/s390/pci): When an SR-IOV VF is hot-unplugged its MMIO resources are freed, but the parent bus keepsCVE-2023-53123 · Linux kernel (arch/s390/pci)High
- Linux kernel (perf): Out-of-bounds write in perf_read_group() via read_size overflow - local rootCVE-2023-6931 · Linux kernel (perf)High
- Linux kernel (IGMP): Use-after-free in IPv4 IGMP - local privilege escalationCVE-2023-6932 · Linux kernel (IGMP)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.