Severity
High
Analysis Summary
CVE-2023-0266
Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by a use-after-free in the ALSA PCM package. An attacker could exploit this vulnerability using missing locks in SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 to gain ring0 access from the system user.
Impact
- Privilege Escalation
Indicators Of Compromise
CVE
- CVE-2023-0266
Affected Vendors
Linux
Affected Products
- Linux Kernel
Remediation
Refer to Linux Kernel GIT Repository for patch, upgrade or suggested workaround information.

