If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.
We recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3623-1 | linux-5.10 security update |
Debian DLA |
DLA-3710-1 | linux security update |
Debian DSA |
DSA-5480-1 | linux security update |
EUVD |
EUVD-2023-44258 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability. We recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc. |
Ubuntu USN |
USN-6285-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6315-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6317-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6318-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6321-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6324-1 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-6325-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6328-1 | Linux kernel (Oracle) vulnerabilities |
Ubuntu USN |
USN-6329-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6330-1 | Linux kernel (GCP) vulnerabilities |
Ubuntu USN |
USN-6331-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6332-1 | Linux kernel (Azure) vulnerabilities |
Ubuntu USN |
USN-6346-1 | Linux kernel (Raspberry Pi) vulnerabilities |
Ubuntu USN |
USN-6348-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6357-1 | Linux kernel (IBM) vulnerabilities |
Ubuntu USN |
USN-6385-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6397-1 | Linux kernel (BlueField) vulnerabilities |
Wed, 05 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability. We recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc. | A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability. We recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc. |
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-03-05T18:48:12.763Z
Reserved: 2023-07-10T20:52:53.660Z
Link: CVE-2023-3609
Updated: 2024-08-02T07:01:56.672Z
Status : Modified
Published: 2023-07-21T21:15:11.743
Modified: 2025-02-13T17:16:57.787
Link: CVE-2023-3609
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN