CVE-2023-51780: Use After Free
An issue was discovered in the Linux kernel before 6.6.8. dovccioctl in net/atm/ioctl.c has a use-after-free because of a vccrecvmsg race condition.
Other sources
Linux Kernel could allow a local authenticated attacker to execute arbitrary code on the system, caused by a use-after-free flaw in the dovccioctl function in net/atm/ioctl.c. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service. on the system.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51780?
CVE-2023-51780 carries a high severity rating due to the presence of a use-after-free vulnerability in the Linux kernel.
How do I fix CVE-2023-51780?
To mitigate CVE-2023-51780, update the Linux kernel to version 6.6.8 or later.
What versions of the Linux kernel are affected by CVE-2023-51780?
CVE-2023-51780 affects Linux kernel versions before 6.6.8, including versions 2.6.12 through 6.6.7.
What is a use-after-free vulnerability in relation to CVE-2023-51780?
In CVE-2023-51780, the use-after-free vulnerability allows an attacker to exploit a race condition that may lead to arbitrary code execution.
Which distributions are impacted by CVE-2023-51780?
CVE-2023-51780 impacts multiple distributions, including Red Hat and Debian, that utilize vulnerable versions of the Linux kernel.