Database/Kernel, userspace & hypervisor
Linux kernel (ALSA): Use-after-free in snd_ctl_elem_read - local privilege escalation
CVSS 7.8CVE-2023-0266Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Use-after-free in snd_ctl_elem_read - local privilege escalation [KEV]
Who can reach it
Local user with access to /dev/snd
What to do
Livepatchable; otherwise drain + reboot. Low exposure on headless GPU nodes - blacklist sound modules
References
Related entries
- Oracle VirtualBox: Core component flaw allowing a low-privileged guest user to take over the host VirtualBoxCVE-2023-21987 · Oracle VirtualBoxHigh
- Linux kernel (io_uring): io_uring fixed-buffer registration gives out-of-bounds access to physical memoryCVE-2023-2598 · Linux kernel (io_uring)High
- Linux kernel (nf_tables): Use-after-free in nft_chain_lookup_byid() - local root (Pwn2Own Vancouver chain)CVE-2023-31248 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): Use-after-free in nf_tables anonymous-set batch processingCVE-2023-32233 · Linux kernel (nf_tables)High
- Linux kernel (mm VMA): StackRot: privilege escalation via non-RCU-protected VMA traversalCVE-2023-3269 · Linux kernel (mm VMA)High
- Linux kernel (nf_tables): UAF in nft_set_lookup_global after mixed named/anonymous set batches - local rootCVE-2023-3390 · Linux kernel (nf_tables)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.