cbcvebase.
CVE-2023-3269
published 2023-07-11

CVE-2023-3269: A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is…

PriorityP179high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
1.48%
71.1th percentile
A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.11-16.3.11-1
linuxlinux_kernel>= 0 < 6.3.11-16.3.11-1
linuxlinux_kernel>= 6.1 < 6.1.376.1.37
linuxlinux_kernel>= 6.2 < 6.3.116.3.11
msrccbl2_hyperv-daemons_5.15.158.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.122.1-2_on_cbl_mariner_2.0
msrccm1_kernel_5.10.188.1-1_on_cbl_mariner_1.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2023-3269 (StackRot/DirtyVMA) is a local privilege escalation via use-after-free in the Linux kernel memory management subsystem due to incorrect lock handling for VMA traversal; monitor for unexpected privilege escalation from local users or container escapes.
  • The vulnerability is tracked under the alias 'DirtyVMA' / 'distros-[DirtyVMA]'; threat intel and log searches should include this alias.
  • On Debian, the vulnerability is fixed in kernel 6.1.37-1 (bookworm) and 6.3.11-1 (forky/sid/trixie); systems running older kernel versions on these distributions should be considered vulnerable.
  • ·Red Hat Enterprise Linux (6, 7, 8, 9) and their kernel-rt variants are NOT affected because the vulnerable code was never introduced into RHEL kernel versions.
  • ·DOC 2 (Exploit-DB 52550) describes a DIFFERENT CVE (CVE-2025-40271, proc_readdir_de rb-tree UAF) and only references CVE-2023-3269 as a technique reference; no IOCs from that document are applicable to CVE-2023-3269 itself.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vulncheck7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.