CVE-2023-0469
published 2023-01-26CVE-2023-0469: A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.32%
24.5th percentile
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.12-1 (bookworm) | linux 6.0.12-1 (bookworm) |
| linux | linux_kernel | < 6.1 | 6.1 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.0.12-1 | 6.0.12-1 |
| linux | linux_kernel | >= 0 < 6.0.12-1 | 6.0.12-1 |
| linux | linux_kernel | >= 0 < 6.0.12-1 | 6.0.12-1 |
| msrc | cbl2_kernel_5.15.122.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_kernel_5.10.188.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu5.8MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2023-03-28·CVSS 5.8
CVE-2023-0469 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the KVM VMX implementation in the Linux kernel did
not properly handle indirect branch prediction isolation between L1 and L2
VMs. An attacker in a guest VM could use this to expose sensitive
information from the host OS or other guest VMs. (CVE-2022-2196)
It was discovered that a race condition existed in the Xen network backend
driver in the Linux kernel when handling dropped packets in certain
circumstances. An attacker could use this to cause a denial of service
(kernel deadlock). (CVE-2022-42328, CVE-2022-42329)
Gerald Lee discovered that the USB Gadget file system implementation in the
Linux kernel contained a race condition, leading to a use-after-fre
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-03-23·CVSS 5.8
CVE-2022-4382 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the KVM VMX implementation in the Linux kernel did
not properly handle indirect branch prediction isolation between L1 and L2
VMs. An attacker in a guest VM could use this to expose sensitive
information from the host OS or other guest VMs. (CVE-2022-2196)
It was discovered that a race condition existed in the Xen network backend
driver in the Linux kernel when handling dropped packets in certain
circumstances. An attacker could use this to cause a denial of service
(kernel deadlock). (CVE-2022-42328, CVE-2022-42329)
Gerald Lee discovered that the USB Gadget file system implementation in the
Linux kernel contained a race condition, leading to a use-after-free
vuln
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2023-03-03·CVSS 4.6
CVE-2022-42896 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the Upper Level Protocol (ULP) subsystem in the
Linux kernel did not properly handle sockets entering the LISTEN state in
certain protocols, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-0461)
It was discovered that the NFSD implementation in the Linux kernel did not
properly handle some RPC messages, leading to a buffer overflow. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2022-43945)
Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Lin
Microsoft
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
vendor_msrc·2023-01-10·CVSS 5.5
CVE-2023-0469 [MEDIUM] CWE-416 A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to
Debian
CVE-2023-0469: linux - A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file...
vendor_debian·2023·CVSS 5.5
CVE-2023-0469 [MEDIUM] CVE-2023-0469: linux - A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file...
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
Scope: local
bookworm: resolved (fixed in 6.0.12-1)
bullseye: resolved
forky: resolved (fixed in 6.0.12-1)
sid: resolved (fixed in 6.0.12-1)
trixie: resolved (fixed in 6.0.12-1)
Red Hat
Kernel: file reference underflow problem in io_uring/filetable in io_install_fixed_file
vendor_redhat·2022-11-23·CVSS 5.5
CVE-2023-0469 [MEDIUM] CWE-191 Kernel: file reference underflow problem in io_uring/filetable in io_install_fixed_file
Kernel: file reference underflow problem in io_uring/filetable in io_install_fixed_file
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
Statement: There is no shipped kernel version seen affected by this problem. These files are not built into our source code.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package:
OSV
linux-hwe-5.19 vulnerabilities
osv·2023-03-28·CVSS 8.8
CVE-2022-2196 [HIGH] linux-hwe-5.19 vulnerabilities
linux-hwe-5.19 vulnerabilities
It was discovered that the KVM VMX implementation in the Linux kernel did
not properly handle indirect branch prediction isolation between L1 and L2
VMs. An attacker in a guest VM could use this to expose sensitive
information from the host OS or other guest VMs. (CVE-2022-2196)
It was discovered that a race condition existed in the Xen network backend
driver in the Linux kernel when handling dropped packets in certain
circumstances. An attacker could use this to cause a denial of service
(kernel deadlock). (CVE-2022-42328, CVE-2022-42329)
Gerald Lee discovered that the USB Gadget file system implementation in the
Linux kernel contained a race condition, leading to a use-after-free
vulnerability in some situations. A local attacker could use this to cause
OSV
linux-oem-6.0 vulnerabilities
osv·2023-03-03·CVSS 6.4
CVE-2023-0461 [MEDIUM] linux-oem-6.0 vulnerabilities
linux-oem-6.0 vulnerabilities
It was discovered that the Upper Level Protocol (ULP) subsystem in the
Linux kernel did not properly handle sockets entering the LISTEN state in
certain protocols, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-0461)
It was discovered that the NFSD implementation in the Linux kernel did not
properly handle some RPC messages, leading to a buffer overflow. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2022-43945)
Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically prox
GHSA
GHSA-p768-xgqw-qmfx: A use-after-free flaw was found in io_uring/filetable
ghsa_unreviewed·2023-01-26
CVE-2023-0469 [MEDIUM] CWE-191 GHSA-p768-xgqw-qmfx: A use-after-free flaw was found in io_uring/filetable
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
OSV
CVE-2023-0469: A use-after-free flaw was found in io_uring/filetable
osv·2023-01-26·CVSS 5.5
CVE-2023-0469 [MEDIUM] CVE-2023-0469: A use-after-free flaw was found in io_uring/filetable
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-40152 woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks
bugzilla·2022-10-13·CVSS 7.5
CVE-2022-40152 [HIGH] CVE-2022-40152 woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks
CVE-2022-40152 woodstox-core: woodstox to serialise XML data was vulnerable to Denial of Service attacks
Those using Xstream to serialize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47434
https://github.com/x-stream/xstream/issues/304
Discussion:
Created xstream tracking bugs for this issue:
Affects: epel-all [bug 2134303]
Affects: fedora-all [bug 2134304]
---
This issue has been addressed in the following products:
RHINT Camel-Q 2.13.2
Via RHSA-2023:0469 https://access.redhat.com/errata/RHSA-2023:0469
---
This issue has been ad
Bugzilla
CVE-2022-40151 xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks
bugzilla·2022-10-13·CVSS 7.5
CVE-2022-40151 [HIGH] CVE-2022-40151 xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks
CVE-2022-40151 xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
https://github.com/x-stream/xstream/issues/304
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47367
Discussion:
Created xstream tracking bugs for this issue:
Affects: epel-all [bug 2134305]
Affects: fedora-all [bug 2134306]
---
This issue has been addressed in the following products:
RHINT Camel-Q 2.13.2
Via RHSA-2023:0469 https://access.redhat.com/errata/RHSA-2023:0469
---
This bug is now closed. Furthe
Bugzilla
CVE-2022-40154 xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks
bugzilla·2022-09-22
CVE-2022-40154 [MEDIUM] CVE-2022-40154 xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks
CVE-2022-40154 xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks
Those using Xstream to serialise XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50393
https://github.com/x-stream/xstream/issues/304
Discussion:
Created xstream tracking bugs for this issue:
Affects: epel-all [bug 2128960]
Affects: fedora-all [bug 2128961]
---
This issue has been addressed in the following products:
RHINT Camel-Q 2.13.2
Via RHSA-2023:0469 https://access.redhat.com/errata/RHSA-2023:0469
---
This bug is now closed. Furt
2023-01-26
Published