CVE-2023-52926
published 2025-02-24CVE-2023-52926: In the Linux kernel, the following vulnerability has been resolved: IORING_OP_READ did not correctly consume the provided buffer list when read i/o returned <…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
IORING_OP_READ did not correctly consume the provided buffer list when
read i/o returned < 0 (except for -EAGAIN and -EIOCBQUEUED return).
This can lead to a potential use-after-free when the completion via
io_rw_done runs at separate context.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.123-1 (bookworm) | linux 6.1.123-1 (bookworm) |
| debian | linux-6.1 | < linux 6.1.123-1 (bookworm) | linux 6.1.123-1 (bookworm) |
| chrome_chrome | — | — | |
| linux | linux | — | — |
| linux | linux | >= 2b188cc1bb857a9d4701ae59aa7768b5124e262e < 72060434a14caea20925e492310d6e680e3f9007 | 72060434a14caea20925e492310d6e680e3f9007 |
| linux | linux | >= 2b188cc1bb857a9d4701ae59aa7768b5124e262e < 6c27fc6a783c8a77c756dd5461b15e465020d075 | 6c27fc6a783c8a77c756dd5461b15e465020d075 |
| linux | linux | >= 2b188cc1bb857a9d4701ae59aa7768b5124e262e < a08d195b586a217d76b42062f88f375a3eedda4d | a08d195b586a217d76b42062f88f375a3eedda4d |
| linux | linux_kernel | >= 0 < 6.1.123-1 | 6.1.123-1 |
| linux | linux_kernel | >= 0 < 6.7.7-1 | 6.7.7-1 |
| linux | linux_kernel | >= 0 < 6.7.7-1 | 6.7.7-1 |
| linux | linux_kernel | >= 5.1 < 6.1.122 | 6.1.122 |
| linux | linux_kernel | >= 6.2 < 6.6.68 | 6.6.68 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-52926
vendor_chrome·2025-06-06·CVSS 7.8
CVE-2023-52926 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2023-52926
Long Term Support Channel Update for ChromeOS
CVE-2023-52926
Red Hat
kernel: io_uring/rw: split io_read() into a helper
vendor_redhat·2025-02-24·CVSS 7.8
CVE-2023-52926 [HIGH] kernel: io_uring/rw: split io_read() into a helper
kernel: io_uring/rw: split io_read() into a helper
In the Linux kernel, the following vulnerability has been resolved:
IORING_OP_READ did not correctly consume the provided buffer list when
read i/o returned < 0 (except for -EAGAIN and -EIOCBQUEUED return).
This can lead to a potential use-after-free when the completion via
io_rw_done runs at separate context.
Statement: The patch 72060434a14caea20925e492310d6e680e3f9007 that is the reason of this issue doesn't lead to any vulnerability. Leaving with Low security impact for now, but could be rejected later based on more analyses.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Ha
Debian
CVE-2023-52926: linux - In the Linux kernel, the following vulnerability has been resolved: IORING_OP_R...
vendor_debian·2023·CVSS 7.8
CVE-2023-52926 [HIGH] CVE-2023-52926: linux - In the Linux kernel, the following vulnerability has been resolved: IORING_OP_R...
In the Linux kernel, the following vulnerability has been resolved: IORING_OP_READ did not correctly consume the provided buffer list when read i/o returned < 0 (except for -EAGAIN and -EIOCBQUEUED return). This can lead to a potential use-after-free when the completion via io_rw_done runs at separate context.
Scope: local
bookworm: resolved (fixed in 6.1.123-1)
bullseye: open
forky: resolved (fixed in 6.7.7-1)
sid: resolved (fixed in 6.7.7-1)
trixie: resolved (fixed in 6.7.7-1)
GHSA
GHSA-mq8h-f329-fxx2: In the Linux kernel, the following vulnerability has been resolved:
IORING_OP_READ did not correctly consume the provided buffer list when
read i/o r
ghsa_unreviewed·2025-02-24
CVE-2023-52926 [HIGH] CWE-416 GHSA-mq8h-f329-fxx2: In the Linux kernel, the following vulnerability has been resolved:
IORING_OP_READ did not correctly consume the provided buffer list when
read i/o r
In the Linux kernel, the following vulnerability has been resolved:
IORING_OP_READ did not correctly consume the provided buffer list when
read i/o returned < 0 (except for -EAGAIN and -EIOCBQUEUED return).
This can lead to a potential use-after-free when the completion via
io_rw_done runs at separate context.
OSV
CVE-2023-52926: In the Linux kernel, the following vulnerability has been resolved: IORING_OP_READ did not correctly consume the provided buffer list when read i/o re
osv·2025-02-24·CVSS 7.8
CVE-2023-52926 [HIGH] CVE-2023-52926: In the Linux kernel, the following vulnerability has been resolved: IORING_OP_READ did not correctly consume the provided buffer list when read i/o re
In the Linux kernel, the following vulnerability has been resolved: IORING_OP_READ did not correctly consume the provided buffer list when read i/o returned < 0 (except for -EAGAIN and -EIOCBQUEUED return). This can lead to a potential use-after-free when the completion via io_rw_done runs at separate context.
No detection rules found.
No public exploits indexed.
2025-02-24
Published