cbcvebase.
CVE-2023-0266
published 2023-01-30

CVE-2023-0266: A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a…

PriorityP181high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-04-20
Exploited in the wild
EPSS
3.70%
88.4th percentile
A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.7-1 (bookworm)linux 6.1.7-1 (bookworm)
googleandroid
googlechrome_chrome
linuxlinux_kernel>= 0 < 5.10.162-15.10.162-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 4.15.0-208.2204.15.0-208.220
linuxlinux_kernel>= 0 < 5.4.0-144.1615.4.0-144.161
linuxlinux_kernel>= 0 < 5.15.0-69.765.15.0-69.76
linuxlinux_kernel>= 4.14 < 56b88b50565cd8b946a2d00b0c83927b7ebb055e56b88b50565cd8b946a2d00b0c83927b7ebb055e
linuxlinux_kernel>= 4.14 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.885.15.88
linuxlinux_kernel>= 5.16 < 6.1.66.1.6
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
msrccbl2_hyperv-daemons_5.15.92.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.92.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_hyperv-daemons_5.10.168.1-1_on_cbl_mariner_1.0
msrccm1_kernel_5.10.168.1-1_on_cbl_mariner_1.0
paloaltopan-os

Detection & IOCsextracted from sources · hover to see the quote

hash56b88b50565cd8b946a2d00b0c83927b7ebb055e
hash72783cf35e6c55bca84c4bb7b776c58152856fd4
urlhttps://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-5.10/alsa-pcm-move-rwsem-lock-inside-snd_ctl_elem_read-to-prevent-uaf.patch?id=72783cf35e6c55bca84c4bb7b776c58152856fd4
commandSNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32
pathsound/core/control.c
  • Monitor for use-after-free exploitation attempts targeting snd_ctl_elem_read in the ALSA subsystem via the compat ioctl path (SNDRV_CTL_IOCTL_ELEM_READ/WRITE32), which can lead to privilege escalation to ring0.
  • Detect unexpected privilege escalation from a local system user to ring0 on Linux systems with ALSA PCM loaded, particularly via the compat path in sound/core/control.c.
  • Check for presence of unpatched kernel versions: fix is included in Linux 6.1.7-1 (Debian bookworm/sid/trixie/forky) and 5.10.162-1 (Debian bullseye). Systems running older versions should be considered at risk.
  • ·As a temporary mitigation, blacklisting ALSA/sound kernel modules prevents the vulnerable code path from loading. This disables sound functionality but blocks exploitation.
  • ·Red Hat Enterprise Linux 6 and 7 (including kernel-rt) are listed as Not Affected for this CVE.
  • ·The vulnerability is exploitable only locally (scope: local) by a normal privileged user, not remotely.

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck7.9HIGH
cisa7.0HIGH
vendor_debian7.9HIGH
vendor_redhat7.9HIGH
vendor_msrc7.8HIGH
vendor_ubuntu6.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.