Vulnerabilities > CVE-2023-4611 - Use After Free vulnerability in Linux Kernel

047910
CVSS 6.3 - MEDIUM
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
HIGH
local
high complexity
linux
CWE-416

Summary

A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.

Vulnerable Configurations

Part Description Count
OS
Linux
5495

Common Weakness Enumeration (CWE)