Vulnerability · NVD
CVE-2023-4622
CVE-2023-4622 : high severity (CVSS 7.8). No tracked catalog app is linked to this CVE.
- Severity (CVSS)
- 7.8
- Exploitation
- 0.6 %
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation.
The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free.
We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c (or backported equivalents).
Show raw CVSS vector
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Android Fixed in May 2024 patch level
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.