CVE-2023-52926

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 24, 2025
Updated: Feb 25, 2025
CWE ID 416

Summary

CVE-2023-52926 is a newly identified vulnerability in the Linux kernel. This issue affects IORING_OP_READ operations, where the kernel fails to properly consume provided buffer lists upon read I/O returns other than -EAGAIN and -EIOCBQUEUED. The consequence of this misbehavior is a potential use-after-free vulnerability. Upon completion, iio_rw_done may run at a separate context, leading to memory corruption and potential crashes or unintended access to sensitive data. Linux users are advised to update their kernel to the latest version, which addresses this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share