A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRVCTLIOCTLELEM{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-0266.json"
[
{
"id": "CVE-2023-0266-2a357343",
"source": "https://github.com/torvalds/linux/commit/becf9e5d553c2389d857a3c178ce80fdb34a02e1",
"target": {
"file": "sound/core/control.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"156634937079670184489074658391952990240",
"24071466279116215125589100774414880756",
"100799015562200835591597646196097126436",
"13435921150168243484887937522283145846",
"335980023798636723456021706383784736293",
"228791040248270060020151070651319047362",
"182220862444328941016572532509540638575",
"60679275231153631124551243132354775981",
"20026401852609680643636655955559753777",
"179841172599773739809645440717577150928",
"191133765329036181550971808943830952738",
"141095517382830223595745010460349969726",
"310441300408239134112109493625680946563",
"95170903033435577117532290686272671741",
"76195054091181634235096657890490650896",
"201207668660522857179237832035589441889",
"280050361625047526653651708809230623113",
"151552483023385573029358464787712820464",
"32695949438916432343089090594733895101",
"174429601523443515769781915574352439114",
"86142769658523359102787968408192496776",
"328923047635188042909823642190750273738",
"325574093222026934758824137894703989496",
"211318030683254941312054646821898312207",
"19267822293056547171400729529043497716",
"24071466279116215125589100774414880756",
"100799015562200835591597646196097126436",
"13435921150168243484887937522283145846",
"335980023798636723456021706383784736293",
"228791040248270060020151070651319047362",
"182220862444328941016572532509540638575",
"60679275231153631124551243132354775981",
"195740731491110906770915484379600899414",
"24998712980245828738150443883676216386",
"159875585019751745179998241126309392028",
"49013831848111826588226355625716768512",
"244612470298170832156923263059584540798",
"331109985328256851214551204800871052430",
"72743551818399806800414876409732158957",
"8397410724259158191143010096279120403",
"86968852153433818903734401328957297751",
"52173725876623069435417926615328570317",
"232136060390041875915544085798878079017",
"75664652500781986559710265283164873121",
"166873116501979541228010804573455344516",
"324825910827614426625161767617769306238",
"181001004250079566472162796644840933164",
"163073019437680511079427556535082852004",
"151552483023385573029358464787712820464",
"60500925855459028639425460475922083985",
"317656085911179422615048400681836666765",
"77579138216497709068211039640900105916",
"81351046887650165044348207412720343022",
"158839277123631745556653325650860797173",
"87313290586109998219799839705715566809",
"288551378298333823225775949159112327778"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
},
{
"id": "CVE-2023-0266-475e1487",
"source": "https://github.com/torvalds/linux/commit/56b88b50565cd8b946a2d00b0c83927b7ebb055e",
"target": {
"file": "sound/core/control.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"186607239495494521708467879435343065615",
"212664839145390613949645046363591000271",
"149113412087965249285789999789759829250",
"38831955080342594281681030311705626136",
"2537851518482303166650449799008285652",
"229097576403856898208282461426400186192",
"40668920917381371557727796699509832693",
"269030988961068168477352165339310355473",
"264786439359970170846022048305017440099",
"12755027338158714618371434865007455202",
"294271495427283444300796166215170512256",
"181425378123470567080983780060214632848",
"20729971361921587414157959717294908533",
"193093375844389302646809722951735316713",
"300087900115591481794084679833867949444",
"307970832768720826231072904430866452061",
"82581469905076220839769012484966017757",
"323474068548694245121911692978069740543",
"87189583438830893185036350527740470068",
"218168557449617070597694659820908984599",
"217050888083783622938933330720759435266",
"172039338081040665959204736151636134986",
"4290970684720465065950032129580990899",
"61328621556464847727911229436532507196",
"143410256173377944969896050248475418633",
"85577603903434646525647638053671613602",
"256411198170490882597005897306046760777",
"150441140108143852574155293743550206083",
"219844924398793537918222388243334597605"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
},
{
"id": "CVE-2023-0266-5e1a90d1",
"source": "https://github.com/torvalds/linux/commit/56b88b50565cd8b946a2d00b0c83927b7ebb055e",
"target": {
"file": "sound/core/control.c",
"function": "snd_ctl_elem_read_user"
},
"digest": {
"function_hash": "110624146881422686246579966075625091336",
"length": 432.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2023-0266-7809b95f",
"source": "https://github.com/torvalds/linux/commit/becf9e5d553c2389d857a3c178ce80fdb34a02e1",
"target": {
"file": "sound/core/control.c",
"function": "snd_ctl_elem_write"
},
"digest": {
"function_hash": "216079839807218838924994109043477061309",
"length": 748.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2023-0266-81596c5b",
"source": "https://github.com/torvalds/linux/commit/becf9e5d553c2389d857a3c178ce80fdb34a02e1",
"target": {
"file": "sound/core/control.c",
"function": "snd_ctl_elem_read"
},
"digest": {
"function_hash": "116718086477403317637027340179778597945",
"length": 554.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2023-0266-affffb56",
"source": "https://github.com/torvalds/linux/commit/56b88b50565cd8b946a2d00b0c83927b7ebb055e",
"target": {
"file": "sound/core/control.c",
"function": "snd_ctl_elem_read"
},
"digest": {
"function_hash": "308790795659577053211440109942634184017",
"length": 1115.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2023-0266-cf54f79a",
"source": "https://github.com/torvalds/linux/commit/becf9e5d553c2389d857a3c178ce80fdb34a02e1",
"target": {
"file": "sound/core/control.c",
"function": "snd_ctl_elem_write_user"
},
"digest": {
"function_hash": "16720538546553303864145564153559637265",
"length": 471.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2023-0266-e071598a",
"source": "https://github.com/torvalds/linux/commit/becf9e5d553c2389d857a3c178ce80fdb34a02e1",
"target": {
"file": "sound/core/control.c",
"function": "snd_ctl_elem_read_user"
},
"digest": {
"function_hash": "3062672723884504777056302003585174085",
"length": 436.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
}
]