CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
5.1%
Use After Free vulnerability in Linux kernel traffic control index filter
(tcindex) allows Privilege Escalation. The imperfect hash area can be
updated while packets are traversing, which will cause a use-after-free
when ‘tcf_exts_exec()’ is called with the destroyed tcf_ext. A local
attacker user can use this vulnerability to elevate its privileges to root.
This issue affects Linux Kernel: from 4.14 before git commit
ee059170b1f7e94e55fa6cadee544e176a6e59c2.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | linux | < 4.15.0-209.220 | UNKNOWN |
ubuntu | 20.04 | noarch | linux | < 5.4.0-147.164 | UNKNOWN |
ubuntu | 22.04 | noarch | linux | < 5.15.0-70.77 | UNKNOWN |
ubuntu | 22.10 | noarch | linux | < 5.19.0-40.41 | UNKNOWN |
ubuntu | 18.04 | noarch | linux-aws | < 4.15.0-1154.167 | UNKNOWN |
ubuntu | 20.04 | noarch | linux-aws | < 5.4.0-1100.108 | UNKNOWN |
ubuntu | 22.04 | noarch | linux-aws | < 5.15.0-1034.38 | UNKNOWN |
ubuntu | 22.10 | noarch | linux-aws | < 5.19.0-1023.24 | UNKNOWN |
ubuntu | 20.04 | noarch | linux-aws-5.15 | < 5.15.0-1034.38~20.04.1 | UNKNOWN |
ubuntu | 18.04 | noarch | linux-aws-5.4 | < 5.4.0-1100.108~18.04.1 | UNKNOWN |
launchpad.net/bugs/cve/CVE-2023-1281
nvd.nist.gov/vuln/detail/CVE-2023-1281
security-tracker.debian.org/tracker/CVE-2023-1281
ubuntu.com/security/notices/USN-5977-1
ubuntu.com/security/notices/USN-5978-1
ubuntu.com/security/notices/USN-6024-1
ubuntu.com/security/notices/USN-6025-1
ubuntu.com/security/notices/USN-6027-1
ubuntu.com/security/notices/USN-6029-1
ubuntu.com/security/notices/USN-6030-1
ubuntu.com/security/notices/USN-6031-1
ubuntu.com/security/notices/USN-6040-1
ubuntu.com/security/notices/USN-6057-1
ubuntu.com/security/notices/USN-6093-1
ubuntu.com/security/notices/USN-6134-1
ubuntu.com/security/notices/USN-6222-1
ubuntu.com/security/notices/USN-6256-1
www.cve.org/CVERecord?id=CVE-2023-1281