A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation.
If tcf_change_indev() fails, fw_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.
We recommend upgrading past commit 0323bce598eea038714f941ce2b22541c46d488f.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSN-0098-1.html | Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/175963/Kernel-Live-Patch-Security-Notice-LSN-0099-1.html | |
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=0323bce598eea038714f941ce2b22541c46d488f | Mailing List Patch Vendor Advisory |
https://kernel.dance/0323bce598eea038714f941ce2b22541c46d488f | Patch Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html | |
https://security.netapp.com/advisory/ntap-20240202-0003/ | |
https://www.debian.org/security/2023/dsa-5480 | Third Party Advisory |
https://www.debian.org/security/2023/dsa-5492 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-07-21 21:15
Updated : 2024-02-02 14:15
NVD link : CVE-2023-3776
Mitre link : CVE-2023-3776
CVE.ORG link : CVE-2023-3776
JSON object : View
Products Affected
debian
- debian_linux
linux
- linux_kernel
CWE
CWE-416
Use After Free