CVE-2023-2235 is an important-severity use-after-free flaw in the Linux kernel Performance Events subsystem. A low-privileged local user can concurrently invoke perf_group_detach() and remove_on_exec, causing unsafe event-group handling that can crash the system or potentially permit local privilege escalation. Red Hat rated the issue CVSS 7.8 with high confidentiality, integrity, and availability impact.
The upstream fix corrects perf_group_detach() so sibling events are re-added to the group red-black tree based on each sibling's PERF_ATTACH_CONTEXT state, rather than the detached event's group-node state. Red Hat shipped kernel fixes for affected RHEL 8 and RHEL 9 variants and related products between June and October 2023; RHEL 8.4 and RHEL 6 are not affected.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat fixed CVE-2023-2235 in the RHEL 8 kernel and kernel-rt components through RHSA-2023:4517 and RHSA-2023:4541.
Red Hat released CVE-2023-2235 fixes for the RHEL 9.0 Extended Update Support kernel and kernel-rt components through RHSA-2023:4137 and RHSA-2023:4138.
Red Hat issued fixes for RHEL 9 kernel, kernel-rt, and kpatch-patch components in RHSA-2023:3723, RHSA-2023:3708, and RHSA-2023:3705.
Red Hat published the record for CVE-2023-2235, an important-severity use-after-free flaw in the Linux kernel Performance Events subsystem that could allow a low-privileged local user to crash a system or potentially escalate privileges.
Peter Zijlstra committed Budimir Markovic's patch for incorrect event-group handling in perf_group_detach(). The change prevents events removed by list_del_event() through remove_on_exec from being re-added to a group's red-black tree.
Red Hat released RHSA-2023:5627 to fix the affected kernel component for RHEL 8.6 Extended Update Support and Red Hat Virtualization 4 for RHEL 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.