Vulnerability Description
A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root. We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 4.14.308 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8cMailing ListPatch
- https://kernel.dance/#8c710f75256bb3cf05ac7b1672c82b92c43f3d28Patch
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230601-0001/Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8cMailing ListPatch
- https://kernel.dance/#8c710f75256bb3cf05ac7b1672c82b92c43f3d28Patch
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230601-0001/Third Party Advisory
FAQ
What is CVE-2023-1829?
CVE-2023-1829 is a vulnerability with a CVSS score of 7.8 (HIGH). A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly de...
How severe is CVE-2023-1829?
CVE-2023-1829 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-1829?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.