Wind River Support Network

HomeDefectsLIN1021-5990
Fixed

LIN1021-5990 : Security Advisory - linux - CVE-2023-1295

Created: Jun 28, 2023    Updated: Jul 12, 2023
Resolved Date: Jun 30, 2023
Found In Version: 10.21.20.1
Fix Version: 10.21.20.18
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.

CREATE(Triage):(User=admin) CVE-2023-1295 (https://nvd.nist.gov/vuln/detail/CVE-2023-1295)

CVEs


Live chat
Online