Use-after-free in Linux kernel's net/sched: cls_fw component
CVE-2023-3776
Key Information:
Badges
What is CVE-2023-3776?
A use-after-free vulnerability exists within the Linux kernel's net/sched: cls_fw component, where improper handling of reference counts could allow an attacker to manipulate the reference counter, potentially causing a local privilege escalation exploit. If an operation such as tcf_change_indev() fails, it triggers an error in fw_set_parms() after modifying the reference counter in tcf_bind_filter(). If an attacker manages to set this counter to zero, it could result in unauthorized access via freed memory, leading to significant security risks. The issue is mitigated in versions following the patch at commit 0323bce598eea038714f941ce2b22541c46d488f.
Affected Version(s)
Kernel 2.6 < 6.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved