SB2023062862 - Time-of-check time-of-use (toctou) race condition in Linux kernel fs
Published: June 28, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Time-of-check time-of-use (toctou) race condition (CVE-ID: CVE-2023-1295)
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to time-of-check time-of-use (toctou) race condition error within the io_close_prep(), io_req_defer_prep(), io_issue_sqe() and io_grab_files() functions in fs/io_uring.c. A local user can execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=788d0824269bef539fe31a785b1517882eafed93
- https://kernel.dance/788d0824269bef539fe31a785b1517882eafed93
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9eac1904d3364254d622bf2c771c4f85cd435fc2
- https://kernel.dance/9eac1904d3364254d622bf2c771c4f85cd435fc2
- https://security.netapp.com/advisory/ntap-20230731-0006/