Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-6932
HistoryDec 19, 2023 - 12:00 a.m.

CVE-2023-6932

2023-12-1900:00:00
ubuntu.com
ubuntu.com
10
linux kernel
use-after-free
local privilege escalation
ipv4
igmp
race condition
rcu
bugzilla
unprivileged user namespaces

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A use-after-free vulnerability in the Linux kernel’s ipv4: igmp component
can be exploited to achieve local privilege escalation. A race condition
can be exploited to cause a timer be mistakenly registered on a RCU read
locked object which is freed by another thread. We recommend upgrading past
commit e2b706c691905fe78468c361aaabc719d0a496f1.

Bugs

Notes

Author Note
Priority reason: By using unprivileged user namespaces, this can be exploited to achieve local privilege escalation.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-221.232UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-170.188UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-92.102UNKNOWN
ubuntu23.10noarchlinux< 6.5.0-15.15UNKNOWN
ubuntu14.04noarchlinux< 3.13.0-195.246UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-250.284UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1164.177UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1117.127UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1052.57UNKNOWN
ubuntu23.10noarchlinux-aws< 6.5.0-1012.12UNKNOWN
Rows per page:
1-10 of 881

References

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%