CVE-2023-2235: Use-after-free in Linux kernel's Performance Events subsystem
A flaw in the Linux Kernel found. A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation.
The perfgroupdetach function did not check the event's siblings' attachstate before calling addeventtogroups(), but removeonexec made it possible to call listdelevent() on before detaching from their group, making it possible to use a dangling pointer causing a use-after-free vulnerability.
Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fd0815f632c24878e325821943edccc7fde947a2
Other sources
A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation.
The perfgroupdetach function did not check the event's siblings' attachstate before calling addeventtogroups(), but removeonexec made it possible to call listdelevent() on before detaching from their group, making it possible to use a dangling pointer causing a use-after-free vulnerability.
We recommend upgrading past commit fd0815f632c24878e325821943edccc7fde947a2.
Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by a use-after-free flaw in the perfgroupdetach function in the Performance Events system. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2235?
CVE-2023-2235 is classified as a local privilege escalation vulnerability in the Linux Kernel.
How do I fix CVE-2023-2235?
To fix CVE-2023-2235, update the Linux Kernel to a patched version such as 5.10.223-1 or 6.1.128-1.
Which versions of the Linux Kernel are affected by CVE-2023-2235?
CVE-2023-2235 affects Linux Kernel versions between 5.13 and 6.3, including specific release candidates.
What are the potential impacts of exploiting CVE-2023-2235?
Exploiting CVE-2023-2235 could allow an attacker to gain elevated privileges on the affected system.
What software components are affected by CVE-2023-2235?
CVE-2023-2235 affects IBM Security Verify Governance, Identity Manager software components and virtual appliances, among other Linux Kernel installations.