boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-0266

Linux Linux Kernel — Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   H   L   N  C  L  H  H    7.9   .0370   89.4   YES
AFFECTED
  Product       Versions  Fixed
  Linux Kernel  4.14 –    —
TIMELINE
  Jan 13  Reserved by Google
  Jan 30  Published (CNA: Google)
  Mar 30  Added to CISA KEV, remediation due 2023-04-20
CWE-416 · CNA: Google · CVSS v3.1 · 5 references · KEV due April 20, 2023

Description

A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 13, 2023ReservedReserved by Google
January 30, 2023PublishedPublished (CNA: Google)
March 30, 2023KEV ADDEDAdded to CISA KEV, remediation due 2023-04-20

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinux Kernel—4.14—

Weaknesses

CWE-416

References (5)

Related

Authoritative record: CVE-2023-0266 at cve.org

Vendors: linux

Weaknesses: CWE-416

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-0266 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.