KEVIntel
7.9
CVSS
High

CVE-2023-0266

PUBLISHED

Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel

Exploited in the wild No user interaction
Vendor
Linux
Product
Linux Kernel
Published
Jan 30, 2023
EPSS

Description

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e

linux cisa nessus_scanner

CVSS scores

CVSS v3.1 7.9 High

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2023-03-30 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 30, 2023

Scanner integrations

Scanner Reference Detected
Nessus https://www.tenable.com/plugins/nessus/236642 Jun 02, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus