PT-2023-5190 · Linux+9 · Linux Kernel+9
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free vulnerability in the Linux kernel's net/sched: sch qfq component can be exploited to achieve local privilege escalation. When the plug qdisc is used as a class of the qfq qdisc, sending network packets triggers use-after-free in
qfq dequeue() due to the incorrect .peek handler of sch plug and lack of error checking in agg dequeue().Recommendations
Upgrade past commit 8fc134fee27f2263988ae38920bc03da416b03d8 to resolve the issue. As a temporary workaround, consider disabling the
qfq dequeue() function until a patch is available. Restrict access to the vulnerable sch qfq component to minimize the risk of exploitation. Avoid using the sch plug qdisc as a class of the qfq qdisc until the issue is resolved.Exploit
Fix
DoS
LPE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu