Use-after-free in Linux kernel - CVE-2023-1252

 

Use-after-free in Linux kernel - CVE-2023-1252

Published: March 23, 2023 / Updated: June 7, 2023


Vulnerability identifier: #VU82761
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-1252
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the Linux kernel’s Ext4 File System in how a user triggers several file operations simultaneously with the overlay FS usage. A local authenticated user can trigger a use-after-free error and escalate privileges on the system.


Affected software

Linux kernel
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
IBM Cloud Pak for Watson AIOps
Technical Support Appliance
Red Hat OpenShift Container Platform
OpenShift Logging
Session Smart Router
IBM Security Verify Governance
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-debug-modules
kernel-core
kernel-debug-modules-extra
kernel-devel
kernel-headers
kernel-modules
kernel-modules-extra
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
perf
python3-perf
kernel-abi-stablelists
kernel-doc
kernel-debug-devel
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel
bpftool
IBM Qradar SIEM

How to mitigate CVE-2023-1252

Install update from vendor's website.

Linux kernel - update to 5.15.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.68, 4.13.33, 4.13.53, 4.14.40
OpenShift Logging - addressed in versions 5.7.10, 5.8.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Technical Support Appliance - update to 3.0.1
kernel (Red Hat package) - addressed in versions 4.18.0-372.91.1.el8_6, 4.18.0-477.75.1.el8_8, 4.18.0-513.5.1.el8_9, 5.14.0-284.90.1.el9_2, 5.14.0-362.8.1.el9_3
kernel-rt (Red Hat package) - addressed in versions 4.18.0-513.5.1.rt7.307.el8_9, 5.14.0-284.90.1.rt14.375.el9_2
kernel-debug-modules - update to 4.18.0-513.18.1.0.1
kernel-core - update to 4.18.0-513.18.1.0.1
kernel-debug-modules-extra - update to 4.18.0-513.18.1.0.1
kernel-devel - update to 4.18.0-513.18.1.0.1
kernel-headers - update to 4.18.0-513.18.1.0.1
kernel-modules - update to 4.18.0-513.18.1.0.1
kernel-modules-extra - update to 4.18.0-513.18.1.0.1
kernel-tools - update to 4.18.0-513.18.1.0.1
kernel-tools-libs - update to 4.18.0-513.18.1.0.1
kernel-tools-libs-devel - update to 4.18.0-513.18.1.0.1
perf - update to 4.18.0-513.18.1.0.1
python3-perf - update to 4.18.0-513.18.1.0.1
kernel-abi-stablelists - update to 4.18.0-513.18.1.0.1
kernel-doc - update to 4.18.0-513.18.1.0.1
kernel-debug-devel - update to 4.18.0-513.18.1.0.1
kernel-debug-core - update to 4.18.0-513.18.1.0.1
kernel-debug - update to 4.18.0-513.18.1.0.1
kernel-cross-headers - update to 4.18.0-513.18.1.0.1
kernel - update to 4.18.0-513.18.1.0.1
bpftool - update to 4.18.0-513.18.1.0.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF02
IBM Security Verify Governance - update to 10.0.2.0.4

External References

Related Security Bulletins