Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause …
高危 CVSS 7.8
摘要
Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()' is called with the destroyed tcf_ext. A local attacker user can use this vulnerability to elevate its privileges to root. This issue affects Linux Kernel: from 4.14 before git commit ee059170b1f7e94e55fa6cadee544e176a6e59c2.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
Lint 边界警告 (2)
以下是本次研判 lint 阶段发现的非阻塞性警告(如引用 URL 未在白名单内)。这些不影响漏洞条目可用性,仅为透明度披露(参 DR-002)。
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://kernel.dance/#ee059170b1f7e94e55fa6cadee544e176a6e59c2 -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://kernel.dance/#ee059170b1f7e94e55fa6cadee544e176a6e59c2
数据来源
- NVD DATABASE
原始链接
- http://www.openwall.com/lists/oss-security/2023/04/11/3 Mailing List
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ee059170b1f7e94e55fa6cadee544e176a6e59c2 Patch
- https://kernel.dance/#ee059170b1f7e94e55fa6cadee544e176a6e59c2 Patch
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html Mailing List
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html Mailing List
- https://security.netapp.com/advisory/ntap-20230427-0004/ Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/04/11/3 Mailing List
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ee059170b1f7e94e55fa6cadee544e176a6e59c2 Patch
- https://kernel.dance/#ee059170b1f7e94e55fa6cadee544e176a6e59c2 Patch
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html Mailing List
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html Mailing List
- https://security.netapp.com/advisory/ntap-20230427-0004/ Third Party Advisory
时间线
- nvd_ingest NVD