NULL Pointer Dereference in Linux Kernel Affects Multiple Versions
CVE-2023-46862

4.7MEDIUM

Key Information:

Vendor

Linux

Vendor
CVE Published:
29 October 2023

What is CVE-2023-46862?

A vulnerability has been identified in the Linux kernel where a race condition during the SQ thread exit can lead to a NULL pointer dereference in the io_uring interface, specifically within the io_uring_show_fdinfo function. This issue may result in application crashes or unexpected behavior, affecting systems running specific versions of the kernel up to 6.5.9. The problem highlights the importance of maintaining up-to-date software and monitoring for patches related to critical kernel functions.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.