CVE-2023-1476
published 2023-11-03CVE-2023-1476: A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between…
PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.23%
14.0th percentile
A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | < 5.14 | 5.14 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rccq-5462-rgcj: A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code
ghsa_unreviewed·2023-11-03
CVE-2023-1476 [HIGH] CWE-416 GHSA-rccq-5462-rgcj: A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code
A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.
Red Hat
kpatch: mm/mremap.c: incomplete fix for CVE-2022-41222
vendor_redhat·2023-03-07·CVSS 7.0
CVE-2023-1476 [HIGH] CWE-416 kpatch: mm/mremap.c: incomplete fix for CVE-2022-41222
kpatch: mm/mremap.c: incomplete fix for CVE-2022-41222
A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.
A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.
Statement: Red Hat Product Security is aware of this issue. Updates will be released as they become available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:1659https://access.redhat.com/security/cve/CVE-2023-1476https://bugzilla.redhat.com/show_bug.cgi?id=2176035https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=97113eb39fa7972722ff490b947d8af023e1f6a2https://access.redhat.com/errata/RHSA-2023:1659https://access.redhat.com/security/cve/CVE-2023-1476https://bugzilla.redhat.com/show_bug.cgi?id=2176035https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=97113eb39fa7972722ff490b947d8af023e1f6a2
2023-11-03
Published