CVE-2023-1295
published 2023-06-28CVE-2023-1295: A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which…
PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.22%
12.4th percentile
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.10.162-1 | 5.10.162-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.11.6 | 5.11.6 |
| linux | linux_kernel | >= 5.6 < 5.10.162 | 5.10.162 |
| linux | linux_kernel | 5.6 – 5.11 | — |
| msrc | cm1_kernel_5.10.188.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3gcx-wjr4-jv32: A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5
ghsa_unreviewed·2023-06-28
CVE-2023-1295 [HIGH] CWE-367 GHSA-3gcx-wjr4-jv32: A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.
OSV
CVE-2023-1295: A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5
osv·2023-06-28·CVSS 7.0
CVE-2023-1295 [HIGH] CVE-2023-1295: A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.
GHSA
Vaadin vulnerable to possible information disclosure of class and method names in RPC response
ghsa·2023-06-22
CVE-2023-25500 [LOW] CWE-1295 Vaadin vulnerable to possible information disclosure of class and method names in RPC response
Vaadin vulnerable to possible information disclosure of class and method names in RPC response
### Description
Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.
https://vaadin.com/security/cve-2023-25500
GHSA
Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting
ghsa·2023-05-16
CVE-2023-32977 [HIGH] CWE-79 Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting
Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting
Jenkins Pipeline: Job Plugin 1292.v27d8cc3e2602 and earlier does not escape the display name of the build that caused an earlier build to be aborted, when "Do not allow concurrent builds" is set.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.
The Jenkins security team is not aware of any plugins that allow the exploitation of this vulnerability, as the build name must be set before the build starts.
Pipeline: Job Plugin 1295.v395eb_7400005 escapes the display name of the build that caused an earlier build to be aborted.
Microsoft
Privilege escalation with IO_RING_OP_CLOSE in the Linux Kernel
vendor_msrc·2023-06-13·CVSS 7.0
CVE-2023-1295 [HIGH] CWE-367 Privilege escalation with IO_RING_OP_CLOSE in the Linux Kernel
Privilege escalation with IO_RING_OP_CLOSE in the Linux Kernel
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: http
Debian
CVE-2023-1295: linux - A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CL...
vendor_debian·2023·CVSS 7.8
CVE-2023-1295 [HIGH] CVE-2023-1295: linux - A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CL...
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.162-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
Red Hat
kernel: io_uring: TOCTOU vulnerability in IORING_OP_CLOSE operation
vendor_redhat·2021-02-01·CVSS 7.8
CVE-2023-1295 [HIGH] CWE-367 kernel: io_uring: TOCTOU vulnerability in IORING_OP_CLOSE operation
kernel: io_uring: TOCTOU vulnerability in IORING_OP_CLOSE operation
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.
A time-of-check to time-of-use flaw was found in the io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel. This flaw allows a local user to elevate their privileges to root.
Statement: No Red Hat products are affected by this flaw, as the `io_uring` subsystem (CONFIG_IO_URING) is not enabled in any shipping kernel release.
Pa
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=788d0824269bef539fe31a785b1517882eafed93https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9eac1904d3364254d622bf2c771c4f85cd435fc2https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959ebhttps://kernel.dance/788d0824269bef539fe31a785b1517882eafed93https://kernel.dance/9eac1904d3364254d622bf2c771c4f85cd435fc2https://security.netapp.com/advisory/ntap-20230731-0006/https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=788d0824269bef539fe31a785b1517882eafed93https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9eac1904d3364254d622bf2c771c4f85cd435fc2https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959ebhttps://kernel.dance/788d0824269bef539fe31a785b1517882eafed93https://kernel.dance/9eac1904d3364254d622bf2c771c4f85cd435fc2https://security.netapp.com/advisory/ntap-20230731-0006/
2023-06-28
Published