Back

HIGH

kernel: DPT I2O controller TOCTOU information disclosure vulnerability

Published Apr 24, 2023

Description

The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.

Affected products

Remediation

Red Hat statement

No Red Hat products are affected by this flaw, as the i2o driver is not included in any shipping kernel release.

Metrics

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 24, 2023
Updated Aug 2, 2024
Reserved Apr 12, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 13, 2023