cbcvebase.
CVE-2023-52654
published 2024-05-14

CVE-2023-52654: In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused…

PriorityP418medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.89%
56.1th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races with unix_stream_read_generic(). The safest fix would be to completely disallow sending io_uring files via sockets via SCM_RIGHT, so there are no possible cycles invloving registered files and thus rendering SCM accounting on the io_uring side unnecessary.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.69-1 (bookworm)linux 6.1.69-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0091bfc81741b8d3aeb3b7ab8636f911b2de6e80 < f2f57f51b53be153a522300454ddb3887722fb2cf2f57f51b53be153a522300454ddb3887722fb2c
linuxlinux>= 0091bfc81741b8d3aeb3b7ab8636f911b2de6e80 < 5a33d385eb36991a91e3dddb189d8679e2aac2be5a33d385eb36991a91e3dddb189d8679e2aac2be
linuxlinux>= 0091bfc81741b8d3aeb3b7ab8636f911b2de6e80 < 705318a99a138c29a512a72c3e0043b3cd7f55f4705318a99a138c29a512a72c3e0043b3cd7f55f4
linuxlinux>= 04df9719df1865f6770af9bc7880874af0e594b2 < 18824f592aad4124d79751bbc1500ea86ac3ff2918824f592aad4124d79751bbc1500ea86ac3ff29
linuxlinux>= 5.10.150 < 5.10.2045.10.204
linuxlinux>= 5.15.75 < 5.15.1435.15.143
linuxlinux>= 5.19.17 < 5.205.20
linuxlinux>= 5.4.220 < 5.4.2645.4.264
linuxlinux>= 6.0.3 < 6.16.1
linuxlinux>= 813d8fe5d30388f73a21d3a2bf46b0a1fd72498c < bcedd497b3b4a0be56f3adf7c7542720eced0792bcedd497b3b4a0be56f3adf7c7542720eced0792
linuxlinux>= c378c479c5175833bb22ff71974cda47d7b05401 < 3fe1ea5f921bf5b71cbfdc4469fb96c05936610e3fe1ea5f921bf5b71cbfdc4469fb96c05936610e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.69-16.1.69-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 5.10.150 < 5.10.2045.10.204
linuxlinux_kernel>= 5.15.75 < 5.15.1435.15.143

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_msrc5.5MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.