Lucene search

K
f5F5F5:K000137584
HistoryNov 15, 2023 - 12:00 a.m.

K000137584 : Linux kernel vulnerability CVE-2023-1829

2023-11-1500:00:00
my.f5.com
26
linux kernel
vulnerability
cve-2023-1829
use-after-free
tcindex
local privilege escalation
traffix sdc

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

17.1%

Security Advisory Description

A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root. We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28. (CVE-2023-1829)

Impact

An attacker with local user access to Traffix SDC can exploit this vulnerability to escalate privileges.