Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-3776
HistoryJul 21, 2023 - 12:00 a.m.

CVE-2023-3776

2023-07-2100:00:00
ubuntu.com
ubuntu.com
12
linux kernel
local privilege escalation
use-after-free
net/sched
cls_fw
tcf_change_indev
fw_set_parms
tcf_bind_filter
bugzilla
redhat
suse
user namespaces

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

A use-after-free vulnerability in the Linux kernel’s net/sched: cls_fw
component can be exploited to achieve local privilege escalation. If
tcf_change_indev() fails, fw_set_parms() will immediately return an error
after incrementing or decrementing the reference counter in
tcf_bind_filter(). If an attacker can control the reference counter and set
it to zero, they can cause the reference to be freed, leading to a
use-after-free vulnerability. We recommend upgrading past commit
0323bce598eea038714f941ce2b22541c46d488f.

Bugs

Notes

Author Note
Priority reason: By using unprivileged user namespaces, this can be exploited to achieve local privilege escalation.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-216.227UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-159.176UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-82.91UNKNOWN
ubuntu23.04noarchlinux< 6.2.0-31.31UNKNOWN
ubuntu14.04noarchlinux< 3.13.0-193.244UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-244.278UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1160.173UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1108.116UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1043.48UNKNOWN
ubuntu23.04noarchlinux-aws< 6.2.0-1010.10UNKNOWN
Rows per page:
1-10 of 801

References

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%