Use-after-free in Linux kernel's net/sched: cls_fw component
CVE-2023-3776

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
21 July 2023

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2023-3776?

A use-after-free vulnerability exists within the Linux kernel's net/sched: cls_fw component, where improper handling of reference counts could allow an attacker to manipulate the reference counter, potentially causing a local privilege escalation exploit. If an operation such as tcf_change_indev() fails, it triggers an error in fw_set_parms() after modifying the reference counter in tcf_bind_filter(). If an attacker manages to set this counter to zero, it could result in unauthorized access via freed memory, leading to significant security risks. The issue is mitigated in versions following the patch at commit 0323bce598eea038714f941ce2b22541c46d488f.

Affected Version(s)

Kernel 2.6 < 6.5

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Alifa Ramdhan of STAR Labs SG
.