CVE-2023-0266
Linux Kernel Use-After-Free Vulnerability
CVSS
—
No CVSS
EPSS
3.7%
p89
KEV
YES
Mar 30, 2023
Exploit Today
77
0-100
Published: — · Last modified: —
3.7%EPSS · 30 days3.7%
2026-08-022026-08-31
Product
Linux / Kernel
Vulnerability
Linux Kernel Use-After-Free Vulnerability
Added to KEV
Mar 30, 2023
Remediate by
Apr 20, 2023
Known ransomware use
No
Summary description
Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.
Required action
Apply updates per vendor instructions.
Notes
https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-5.10/alsa-pcm-move-rwsem-lock-inside-snd_ctl_elem_read-to-prevent-uaf.patch?id=72783cf35e6c55bca84c4bb7b776c58152856fd4; https://nvd.nist.gov/vuln/detail/CVE-2023-0266
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-533627.8 HIG41.5%
KEV—62Linux Kernel Unspecified Vulnerability3dCVE-2026-314317.8 HIG100.0%
KEV—80Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability34dCVE-2025-383527.8 HIG68.0%
KEV—70Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability32dCVE-2024-10867.8 HIG98.0%
KEV—79Linux Kernel Use-After-Free Vulnerability24dCVE-2022-25865.3 MED95.4%
KEV—79Linux Kernel Use-After-Free Vulnerability11dCVE-2022-09957.8 HIG95.1%
KEV—79Linux Kernel Out-of-Bounds Write Vulnerability5d