CVE-2023-2598
A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation.
- Affected products
- Alt Linux, Linux Kernel
- Linux Linux Kernel
- < 6.3.2
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 1.4% (70th percentile)
- Weakness
- CWE-787, CWE-416
- NVD status
- Modified
- Published
- 2023-06-01
CVE-2023-2598 at NVD
12 known exploits for CVE-2023-2598
Proof-of-concept code and exploit modules indexed by Sploitus
io_uring_LPE-CVE-2024-0582
CVE-2023-2598
CVE-2023-2598
io_uring_LPE-CVE-2023-2598
CVE-2023-2598
kernel-exploit-factory
Exploit for CVE-2025-2598
Exploit for Out-of-bounds Write in Linux Linux_Kernel
Exploit for Use After Free in Linux Linux_Kernel
Exploit for Out-of-bounds Write in Linux Linux_Kernel
Exploit for Use After Free in Linux Linux_Kernel
Exploit for Out-of-bounds Write in Linux Linux_Kernel