Vulnerability record · CVE-2023-0266 · published 30 January 2023
CVE-2023-0266: Linux Kernel ALSA PCM use-after-free allows local privilege escalation
Debian · Debian Linux
The ALSA PCM subsystem in the Linux kernel is missing locks around SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32, creating a use-after-free condition. A local user can trigger the race to corrupt kernel memory and escalate privileges. The flaw is confirmed as exploited in the wild per CISA KEV.
Description
A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityActive exploitation is confirmed by CISA KEV and the flaw yields kernel-level privilege escalation, though it requires local access and a race condition.
What it is
The ALSA PCM subsystem in the Linux kernel is missing locks around SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32, creating a use-after-free condition. A local user can trigger the race to corrupt kernel memory and escalate privileges. The flaw is confirmed as exploited in the wild per CISA KEV.
Impact
An attacker with a local account gains ring0 (kernel) access, effectively full control of the host and the ability to bypass all user-space protections.
Attack surface
Reached locally through ALSA control ioctls on a system with the vulnerable kernel; the CVSS vector (AV:L/PR:L/UI:N) indicates a local attacker with low privileges and no user interaction.
Exploitation
CVE-2023-0266 is listed in CISA KEV with a 2023-04-20 remediation due date, confirming active exploitation; EPSS 30-day probability is 0.037 (89th percentile).
What to do
- Apply the upstream kernel patches (commits 56b88b50565cd8b946a2d00b0c83927b7ebb055e and becf9e5d553c2389d857a3c178ce80fdb34a02e1) or the vendor kernel update.
- Update Debian and other distribution kernels per vendor advisories; reboot to load the fixed kernel.
- Restrict local shell and container access to trusted users, since exploitation requires a local account.
- Where patching is delayed, consider blocking or restricting access to ALSA control device nodes for untrusted users.
- Track KEV remediation deadlines and verify kernel versions across all hosts, including containers sharing the host kernel.
Detection
- Monitor for unexpected kernel crashes or oops messages referencing ALSA PCM or snd_ctl_elem_read/write.
- Alert on privilege changes from non-root to root or ring0 activity outside normal administrative workflows.
- Audit local user accounts and processes invoking ALSA control ioctls, especially from containers or unprivileged services.
- Check kernel versions against the patched commits and flag hosts still running vulnerable builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-0266 to the Known Exploited Vulnerabilities catalog on 30 March 2023 as "Linux Kernel Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 20 April 2023.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-5.10/alsa-pcm-move-rwsem-lock-inside- | Mailing ListPatchVendor Advisory |
| https://github.com/torvalds/linux/commit/56b88b50565cd8b946a2d00b0c83927b7ebb055e | Patch |
| https://github.com/torvalds/linux/commit/becf9e5d553c2389d857a3c178ce80fdb34a02e1 | Patch |
| https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html | Mailing ListThird Party Advisory |
| https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-5.10/alsa-pcm-move-rwsem-lock-inside- | Mailing ListPatchVendor Advisory |
| https://github.com/torvalds/linux/commit/56b88b50565cd8b946a2d00b0c83927b7ebb055e | Patch |
| https://github.com/torvalds/linux/commit/becf9e5d553c2389d857a3c178ce80fdb34a02e1 | Patch |
| https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html | Mailing ListThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-0266 | US Government Resource |
Track CVE-2023-0266 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-0266), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.