cbcvebase.
CVE-2023-52646
published 2024-04-26

CVE-2023-52646: In the Linux kernel, the following vulnerability has been resolved: aio: fix mremap after fork null-deref Commit e4a0d3e720e7 ("aio: Make it possible to remap…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved: aio: fix mremap after fork null-deref Commit e4a0d3e720e7 ("aio: Make it possible to remap aio ring") introduced a null-deref if mremap is called on an old aio mapping after fork as mm->ioctx_table will be set to NULL. [[email protected]: fix 80 column issue]

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.15-1 (bookworm)linux 6.1.15-1 (bookworm)
linuxlinux
linuxlinux>= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < 808f1e4b5723ae4eda724d2ad6f6638905eefd95808f1e4b5723ae4eda724d2ad6f6638905eefd95
linuxlinux>= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < d8dca1bfe9adcae38b35add64977818c0c13dd22d8dca1bfe9adcae38b35add64977818c0c13dd22
linuxlinux>= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < 4326d0080f7e84fba775da41d158f46cf9d3f1c24326d0080f7e84fba775da41d158f46cf9d3f1c2
linuxlinux>= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < c261f798f7baa8080cf0214081d43d5f86bb073fc261f798f7baa8080cf0214081d43d5f86bb073f
linuxlinux>= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < 178993157e8c50aef7f35d7d6d3b44bb428199e1178993157e8c50aef7f35d7d6d3b44bb428199e1
linuxlinux>= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < af126acf01a12bdb04986fd26fc2eb3b40249e0daf126acf01a12bdb04986fd26fc2eb3b40249e0d
linuxlinux>= e4a0d3e720e7e508749c1439b5ba3aff56c92976 < 81e9d6f8647650a7bead74c5f926e29970e834d181e9d6f8647650a7bead74c5f926e29970e834d1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 0 < 6.1.15-16.1.15-1
linuxlinux_kernel>= 3.19 < 4.14.3064.14.306
linuxlinux_kernel>= 4.15 < 4.19.2734.19.273
linuxlinux_kernel>= 4.20 < 5.4.2325.4.232
linuxlinux_kernel>= 5.11 < 5.15.955.15.95
linuxlinux_kernel>= 5.16 < 6.1.136.1.13
linuxlinux_kernel>= 5.5 < 5.10.1695.10.169
ubuntulinux-aws
ubuntulinux-fips
ubuntulinux-lts-xenial

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.