In the Linux kernel, the following vulnerability has been resolved: bpf: Fix too early release of tcx_entry Pedro Pinto and later independently also Hyunwoo Kim and Wongi Lee reported an issue that…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix too early release of tcx_entry Pedro Pinto and later independently also Hyunwoo Kim and Wongi Lee reported an issue that the tcx_entry can be released too early leading to a use after free (UAF) when an active old-style ingress or clsact qdisc with a shared tc block is later replaced by another ingress or clsact instance. Essentially, the sequence to trigger the UAF (one example) can be as follows: 1. A network n…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/1cb6f0bae50441f4b4b32a28315853b279c7404e Mailing List
- https://git.kernel.org/stable/c/230bb13650b0f186f540500fd5f5f7096a822a2a Mailing List
- https://git.kernel.org/stable/c/f61ecf1bd5b562ebfd7d430ccb31619857e80857 Mailing List
- https://git.kernel.org/stable/c/1cb6f0bae50441f4b4b32a28315853b279c7404e Mailing List
- https://git.kernel.org/stable/c/230bb13650b0f186f540500fd5f5f7096a822a2a Mailing List
- https://git.kernel.org/stable/c/f61ecf1bd5b562ebfd7d430ccb31619857e80857 Mailing List
Timeline
- nvd_ingest NVD