Database/Kernel, userspace & hypervisor
Linux kernel (AF_UNIX): Use-after-free in unix_stream_sendpage - local privilege escalation, no capabilities needed
CVSS 6.6CVE-2023-4622Kernel, userspace & hypervisorcurated
Impact
Use-after-free in unix_stream_sendpage - local privilege escalation, no capabilities needed
Who can reach it
Any tenant process in a container
What to do
Livepatchable; otherwise drain + reboot. Note this one needs no CAP_NET_ADMIN, so userns hardening does not help
References
Related entries
- Linux kernel (net/sched ETS): Out-of-bounds indexing in the ETS qdisc - memory corruption from CAP_NET_ADMINCVE-2025-21692 · Linux kernel (net/sched ETS)Medium
- Linux kernel (drivers/bus/fsl-mc): The fsl-mc bus read its driver_override string without holding the device lock, soCVE-2026-53115 · Linux kernel (drivers/bus/fsl-mc)Medium
- Linux kernel (drivers/pci): The PCI bus match callback read driver_override without the device lock, so the overrideCVE-2026-53120 · Linux kernel (drivers/pci)Medium
- Linux KVM (arch/x86/kvm/svm.c, vmx.c) and Xen 4.3.x-4.6.x - #AC exception handling: A guest raises alignment-checkCVE-2015-5307 · Linux KVM (arch/x86/kvm/svm.c, vmx.c) and Xen 4.3.x-4.6.x - #AC exception handlingMedium
- Xen PCI passthrough - device memory/IO decoding and host memory initialisation: With memory and I/O decoding leftCVE-2015-8553 · Xen PCI passthrough - device memory/IO decoding and host memory initialisationMedium
- IBM GPFS kernel module (mmap path): An unprivileged user panics the kernel on a GPFS node just by mmap-ing a file onCVE-2018-1782 · IBM GPFS kernel module (mmap path)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.