← Vulnerability feed

Vulnerability record · CVE-2023-0266 · published 30 January 2023

CVE-2023-0266: Linux Kernel ALSA PCM use-after-free allows local privilege escalation

Debian · Debian Linux

The ALSA PCM subsystem in the Linux kernel is missing locks around SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32, creating a use-after-free condition. A local user can trigger the race to corrupt kernel memory and escalate privileges. The flaw is confirmed as exploited in the wild per CISA KEV.

7.0 CVSS 3.1 High CISA KEV since 30 Mar 2023 EPSS 3.7% · top 10.7% CWE-416 · Use after free
7.0CVSS 3.1 base score
3.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityActive exploitation is confirmed by CISA KEV and the flaw yields kernel-level privilege escalation, though it requires local access and a race condition.

What it is

The ALSA PCM subsystem in the Linux kernel is missing locks around SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32, creating a use-after-free condition. A local user can trigger the race to corrupt kernel memory and escalate privileges. The flaw is confirmed as exploited in the wild per CISA KEV.

Impact

An attacker with a local account gains ring0 (kernel) access, effectively full control of the host and the ability to bypass all user-space protections.

Attack surface

Reached locally through ALSA control ioctls on a system with the vulnerable kernel; the CVSS vector (AV:L/PR:L/UI:N) indicates a local attacker with low privileges and no user interaction.

Exploitation

CVE-2023-0266 is listed in CISA KEV with a 2023-04-20 remediation due date, confirming active exploitation; EPSS 30-day probability is 0.037 (89th percentile).

What to do

  • Apply the upstream kernel patches (commits 56b88b50565cd8b946a2d00b0c83927b7ebb055e and becf9e5d553c2389d857a3c178ce80fdb34a02e1) or the vendor kernel update.
  • Update Debian and other distribution kernels per vendor advisories; reboot to load the fixed kernel.
  • Restrict local shell and container access to trusted users, since exploitation requires a local account.
  • Where patching is delayed, consider blocking or restricting access to ALSA control device nodes for untrusted users.
  • Track KEV remediation deadlines and verify kernel versions across all hosts, including containers sharing the host kernel.

Detection

  • Monitor for unexpected kernel crashes or oops messages referencing ALSA PCM or snd_ctl_elem_read/write.
  • Alert on privilege changes from non-root to root or ring0 activity outside normal administrative workflows.
  • Audit local user accounts and processes invoking ALSA control ioctls, especially from containers or unprivileged services.
  • Check kernel versions against the patched commits and flag hosts still running vulnerable builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-0266 to the Known Exploited Vulnerabilities catalog on 30 March 2023 as "Linux Kernel Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 20 April 2023.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-0266 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2023-0266), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.