CVE-2023-4611
published 2023-08-29CVE-2023-4611: A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and…
PriorityP428medium6.3CVSS 3.1
AVLACHPRLUINSUCHINAH
EPSS
0.26%
17.1th percentile
A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.4.11-1 (forky) | linux 6.4.11-1 (forky) |
| linux | linux_kernel | < 6.5 | 6.5 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| msrc | cbl2_kernel_5.15.135.1-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
osv6.3MEDIUM
vendor_debian7.0LOW
vendor_redhat7.0HIGH
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
Microsoft
Use after free race between mbind() and vma-locked page fault
vendor_msrc·2023-08-08·CVSS 6.3
CVE-2023-4611 [HIGH] CWE-416 Use after free race between mbind() and vma-locked page fault
Use after free race between mbind() and vma-locked page fault
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https
Red Hat
kernel: Use after free race between mbind() and VMA-locked page fault
vendor_redhat·2023-07-28·CVSS 7.0
CVE-2023-4611 [HIGH] CWE-416 kernel: Use after free race between mbind() and VMA-locked page fault
kernel: Use after free race between mbind() and VMA-locked page fault
A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.
A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.
Statement: Affected patch was not built in any of the shipped RHEL Kernel.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the R
Debian
CVE-2023-4611: linux - A use-after-free flaw was found in mm/mempolicy.c in the memory management subsy...
vendor_debian·2023·CVSS 7.0
CVE-2023-4611 [HIGH] CVE-2023-4611: linux - A use-after-free flaw was found in mm/mempolicy.c in the memory management subsy...
A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.4.11-1)
sid: resolved (fixed in 6.4.11-1)
trixie: resolved (fixed in 6.4.11-1)
GHSA
GHSA-95mw-86qw-9v54: A use-after-free flaw was found in mm/mempolicy
ghsa_unreviewed·2023-08-30
CVE-2023-4611 [MEDIUM] CWE-416 GHSA-95mw-86qw-9v54: A use-after-free flaw was found in mm/mempolicy
A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.
OSV
CVE-2023-4611: A use-after-free flaw was found in mm/mempolicy
osv·2023-08-29·CVSS 6.3
CVE-2023-4611 [MEDIUM] CVE-2023-4611: A use-after-free flaw was found in mm/mempolicy
A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2023-4611https://bugzilla.redhat.com/show_bug.cgi?id=2227244https://www.spinics.net/lists/stable-commits/msg310136.htmlhttps://access.redhat.com/security/cve/CVE-2023-4611https://bugzilla.redhat.com/show_bug.cgi?id=2227244https://www.spinics.net/lists/stable-commits/msg310136.html
2023-08-29
Published