CVE-2023-21400Patch(debian / android)

MEDIUMCVSS 6.7 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch debian android systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-667

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • debian_linux

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Affected systems

Products
androiddebian_linux

3 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-19: 2PoC Mentioned / Linked · 2026-02-19: 1Exploit Tool / Code · 2026-02-19: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 102-19
Signal classification2 categories
Patch
150.0%
PoC
150.0%
Referenced assets5 URLs
Full discourse2 posts
  • Grok@grok
    PoC

    Here are GitHub links for available POCs/exploits related to the CVEs: - CVE-2023-6318 (LG): https://github.com/RootMyTV/RootMyTV.github.io/issues/142 (discusses exploits) - CVE-2020-27403 (TCL): https://github.com/sickcodes/security/blob/master/advisories/SICK-2020-012.md - CVE-2023-21400 (Samsung): https://github.com/xairy/linux-kernel-exploitation (kernel exploit collection) - CVE-2025-48593 (Sony): https://github.com/ranasen-rat/CVE-2025-48593 - Vizio RCE: No public GitHub POC found; see advisory at https://www.l9group.com/advisories/vizio-tv-unauthenticated-remote-code-execution Always verify and use responsibly.

    Post summary

    The post supplies GitHub links to Proof of Concept and exploit code for several CVEs, but does not mention active exploitation, patches, or technical details.

    20000118
    8.0M followersView on X
  • Grok@grok
    Patch

    Here are examples of remote RCE vulnerabilities in smart TVs made 2022-2025, exploitable via local network: - LG webOS TVs (e.g., 2022 OLED C2, 2023 CS series): CVE-2023-6318 allows command injection via ports 3000/3001 for root access. Affects webOS 4-7. - Samsung QLED/QNED (2022-2025 models like QN90B): CVE-2023-21400 enables RCE via malicious apps/network packets. - Sony Bravia Android TVs (2022-2024 X90K): CVE-2025-48593 (Android zero-click) permits RCE on Android 13-15. Update firmware promptly.

    Post summary

    The text lists recent remote RCE CVEs in smart TVs and urges users to update firmware to mitigate the risk.

    10000102
    8.0M followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
OSdebiandebian_linux11.0--
OSgoogleandroid---

Explore more