CVE-2023-52646
published 2024-04-26CVE-2023-52646: In the Linux kernel, the following vulnerability has been resolved: aio: fix mremap after fork null-deref Commit e4a0d3e720e7 ("aio: Make it possible to remap…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
aio: fix mremap after fork null-deref
Commit e4a0d3e720e7 ("aio: Make it possible to remap aio ring") introduced
a null-deref if mremap is called on an old aio mapping after fork as
mm->ioctx_table will be set to NULL.
[[email protected]: fix 80 column issue]
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.15-1 (bookworm) | linux 6.1.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < 808f1e4b5723ae4eda724d2ad6f6638905eefd95 | 808f1e4b5723ae4eda724d2ad6f6638905eefd95 |
| linux | linux | >= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < d8dca1bfe9adcae38b35add64977818c0c13dd22 | d8dca1bfe9adcae38b35add64977818c0c13dd22 |
| linux | linux | >= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < 4326d0080f7e84fba775da41d158f46cf9d3f1c2 | 4326d0080f7e84fba775da41d158f46cf9d3f1c2 |
| linux | linux | >= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < c261f798f7baa8080cf0214081d43d5f86bb073f | c261f798f7baa8080cf0214081d43d5f86bb073f |
| linux | linux | >= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < 178993157e8c50aef7f35d7d6d3b44bb428199e1 | 178993157e8c50aef7f35d7d6d3b44bb428199e1 |
| linux | linux | >= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < af126acf01a12bdb04986fd26fc2eb3b40249e0d | af126acf01a12bdb04986fd26fc2eb3b40249e0d |
| linux | linux | >= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < 81e9d6f8647650a7bead74c5f926e29970e834d1 | 81e9d6f8647650a7bead74c5f926e29970e834d1 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 0 < 6.1.15-1 | 6.1.15-1 |
| linux | linux_kernel | >= 3.19 < 4.14.306 | 4.14.306 |
| linux | linux_kernel | >= 4.15 < 4.19.273 | 4.19.273 |
| linux | linux_kernel | >= 4.20 < 5.4.232 | 5.4.232 |
| linux | linux_kernel | >= 5.11 < 5.15.95 | 5.15.95 |
| linux | linux_kernel | >= 5.16 < 6.1.13 | 6.1.13 |
| linux | linux_kernel | >= 5.5 < 5.10.169 | 5.10.169 |
| ubuntu | linux-aws | — | — |
| ubuntu | linux-fips | — | — |
| ubuntu | linux-lts-xenial | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-52646: In the Linux kernel, the following vulnerability has been resolved: aio: fix mremap after fork null-deref Commit e4a0d3e720e7 ("aio: Make it possible
osv·2024-04-26·CVSS 5.5
CVE-2023-52646 [MEDIUM] CVE-2023-52646: In the Linux kernel, the following vulnerability has been resolved: aio: fix mremap after fork null-deref Commit e4a0d3e720e7 ("aio: Make it possible
In the Linux kernel, the following vulnerability has been resolved: aio: fix mremap after fork null-deref Commit e4a0d3e720e7 ("aio: Make it possible to remap aio ring") introduced a null-deref if mremap is called on an old aio mapping after fork as mm->ioctx_table will be set to NULL. [[email protected]: fix 80 column issue]
GHSA
GHSA-52h9-53cv-vm4j: In the Linux kernel, the following vulnerability has been resolved:
aio: fix mremap after fork null-deref
Commit e4a0d3e720e7 ("aio: Make it possibl
ghsa_unreviewed·2024-04-26
CVE-2023-52646 [MEDIUM] CWE-476 GHSA-52h9-53cv-vm4j: In the Linux kernel, the following vulnerability has been resolved:
aio: fix mremap after fork null-deref
Commit e4a0d3e720e7 ("aio: Make it possibl
In the Linux kernel, the following vulnerability has been resolved:
aio: fix mremap after fork null-deref
Commit e4a0d3e720e7 ("aio: Make it possible to remap aio ring") introduced
a null-deref if mremap is called on an old aio mapping after fork as
mm->ioctx_table will be set to NULL.
[[email protected]: fix 80 column issue]
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-15·CVSS 5.5
CVE-2026-43414 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Thermal drivers;
- USB over IP driver;
- File systems infrastructure;
- Ext4 file system;
- Network file system (NFS) server daemon;
- SMB network file system;
- Tracing infrastructure;
- B.A.T.M.A.N. meshing protocol;
- C
Red Hat
kernel: aio: fix mremap after fork null-deref
vendor_redhat·2024-04-26·CVSS 5.5
CVE-2023-52646 [MEDIUM] CWE-476 kernel: aio: fix mremap after fork null-deref
kernel: aio: fix mremap after fork null-deref
In the Linux kernel, the following vulnerability has been resolved:
aio: fix mremap after fork null-deref
Commit e4a0d3e720e7 ("aio: Make it possible to remap aio ring") introduced
a null-deref if mremap is called on an old aio mapping after fork as
mm->ioctx_table will be set to NULL.
[[email protected]: fix 80 column issue]
A flaw was found in the Linux kernel’s Asynchronous I/O (AIO) subsystem. The issue arises due to a NULL pointer dereference (null-deref) when using the mremap() function after a fork operation, specifically on old AIO mappings. The vulnerability occurs because the ioctx_table is set to NULL after the fork, leading to the potential for system crashes when mremap() is called on these outdated mappings.
The problem was intr
Debian
CVE-2023-52646: linux - In the Linux kernel, the following vulnerability has been resolved: aio: fix mr...
vendor_debian·2023·CVSS 5.5
CVE-2023-52646 [MEDIUM] CVE-2023-52646: linux - In the Linux kernel, the following vulnerability has been resolved: aio: fix mr...
In the Linux kernel, the following vulnerability has been resolved: aio: fix mremap after fork null-deref Commit e4a0d3e720e7 ("aio: Make it possible to remap aio ring") introduced a null-deref if mremap is called on an old aio mapping after fork as mm->ioctx_table will be set to NULL. [[email protected]: fix 80 column issue]
Scope: local
bookworm: resolved (fixed in 6.1.15-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.15-1)
sid: resolved (fixed in 6.1.15-1)
trixie: resolved (fixed in 6.1.15-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/178993157e8c50aef7f35d7d6d3b44bb428199e1https://git.kernel.org/stable/c/4326d0080f7e84fba775da41d158f46cf9d3f1c2https://git.kernel.org/stable/c/808f1e4b5723ae4eda724d2ad6f6638905eefd95https://git.kernel.org/stable/c/81e9d6f8647650a7bead74c5f926e29970e834d1https://git.kernel.org/stable/c/af126acf01a12bdb04986fd26fc2eb3b40249e0dhttps://git.kernel.org/stable/c/c261f798f7baa8080cf0214081d43d5f86bb073fhttps://git.kernel.org/stable/c/d8dca1bfe9adcae38b35add64977818c0c13dd22https://git.kernel.org/stable/c/178993157e8c50aef7f35d7d6d3b44bb428199e1https://git.kernel.org/stable/c/4326d0080f7e84fba775da41d158f46cf9d3f1c2https://git.kernel.org/stable/c/808f1e4b5723ae4eda724d2ad6f6638905eefd95https://git.kernel.org/stable/c/81e9d6f8647650a7bead74c5f926e29970e834d1https://git.kernel.org/stable/c/af126acf01a12bdb04986fd26fc2eb3b40249e0dhttps://git.kernel.org/stable/c/c261f798f7baa8080cf0214081d43d5f86bb073fhttps://git.kernel.org/stable/c/d8dca1bfe9adcae38b35add64977818c0c13dd22
2024-04-26
Published