CVE-2023-1829 | Date: (C)2023-04-20 (M)2024-05-24 |
A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation.��The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure.��A local attacker user can use this vulnerability to elevate its privileges to root.
We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.
CVSS Score and Metrics +CVSS Score and Metrics -CVSS V3 Severity: | CVSS V2 Severity: |
CVSS Score : 7.8 | CVSS Score : |
Exploit Score: 1.8 | Exploit Score: |
Impact Score: 5.9 | Impact Score: |
|
CVSS V3 Metrics: | CVSS V2 Metrics: |
Attack Vector: LOCAL | Access Vector: |
Attack Complexity: LOW | Access Complexity: |
Privileges Required: LOW | Authentication: |
User Interaction: NONE | Confidentiality: |
Scope: UNCHANGED | Integrity: |
Confidentiality: HIGH | Availability: |
Integrity: HIGH | |
Availability: HIGH | |
| |