CVE-2023-4611

Executive Summary

A use‑after‑free vulnerability in Linux kernel’s memory‑management subsystem (mm/mempolicy.c) arises from a race between mbind() and a VMA‑locked page fault. A local attacker can exploit this to crash the system or leak kernel memory contents, potentially leading to privilege escalation.


Authoritative CVE Metadata - CVSS Base Score: 7.0 (HIGH) - Published: 2023-08-29T22:15:09.397 - Last Modified: 2026-09-11T16:15:24.103

Original Description: A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.

"If we learn to open our hearts, anyone, including the people who drive us crazy, can be our teacher."

— Pema Chodron
Source: NVD