CVE-2023-2598
HIGH 7.8EPSS 1.4%
A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 1.37% chance of exploitation in the next 30 days, 70th percentile
- Published
- 2023-06-01
- Updated
- 2025-04-23
Proof-of-concept exploits (9)
- http://www.openwall.com/lists/oss-security/2024/04/24/3
- 101010zyl/CVE-2024-05825★ · 2024-12-15
- 101010zyl/CVE-2024-0582-dataonly5★ · 2024-12-15
- LLfam/CVE-2023-25981★ · 2024-11-06
- SpongeBob-369/CVE-2023-25983★ · 2025-08-20
- SpongeBob-369/CVE-2025-25983★ · 2025-08-20
- cainiao159357/CVE-2023-25980★ · 2024-08-31
- ysanatomic/io_uring_LPE-CVE-2023-259890★ · 2023-11-23
- ysanatomic/io_uring_LPE-CVE-2024-0582101★ · 2024-03-29