CVE-2023-2598
A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows...
- Published
- Jun 1, 2023
- Updated
- Apr 23, 2025
- Assigning CNA
- redhat
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 70.3%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation.
Sources
5- CVE-2023-2598Exploit
Technical analysis and proof-of-concept exploit for CVE-2023-2598, a Linux kernel privilege escalation vulnerability in io_uring's buffer registration, with detailed explanation of Compound Page and folio internals.
- CVE-2023-2598Exploit
C exploit for CVE-2023-2598, a Linux kernel privilege escalation vulnerability in io_uring. Achieves root shell via socket-based memory corruption and KASLR bypass.
- CVE-2023-2598Exploit
The exploitation of CVE-2023-2598 about io_uring
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.