CVE-2023-1829
גבוהה 7.8
תיאור (מקור, אנגלית)
A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root. We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ .
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-416
מוצרים מושפעים
linux: linux kernel
קישורים
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Mailing ListPatch
- https://kernel.dance/#8c710f75256bb3cf05ac7b1672c82b92c43f3d28 Patch
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=… Mailing ListPatch
- https://kernel.dance/#8c710f75256bb3cf05ac7b1672c82b92c43f3d28 Patch
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html Mailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230601-0001/ Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html Mailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230601-0001/ Third Party Advisory