cbcvebase.
CVE-2023-2612
published 2023-05-31

CVE-2023-2612: Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some…

PriorityP417medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.28%
20.7th percentile
Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonical_ltdubuntu-linux< 02b47547824b1cd0d55c6744f91886f04de8947e02b47547824b1cd0d55c6744f91886f04de8947e
linuxlinux_kernel>= 0 < 5.4.0-150.1675.4.0-150.167
linuxlinux_kernel>= 0 < 5.15.0-73.805.15.0-73.80
linuxlinux_kernel>= 0 < 5.4.0-150.1675.4.0-150.167
linuxlinux_kernel>= 0 < 5.15.0-73.805.15.0-73.80

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.