CVE-2023-0266 HIGH

CVE-2023-0266: Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel

Vendor Linux
Product Linux Kernel
Weakness CWE-416
KEV Status Known Exploited
Published January 30, 2023
Last update October 21, 2025

CVSS base score

7.9/10
Attack vector Adjacent
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H

What the vulnerability does

01Description

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e

CISA mandated remediation

02CISA Required Action

Apply updates per vendor instructions.

Key dates

03Disclosure timeline

January 30, 2023 CVE published
October 21, 2025 Record updated