THREATOPS
THREAT OPSThreat News › [NVD] CVE-2023-3609 (HIGH 7.8) — A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in t

[NVD] CVE-2023-3609 (HIGH 7.8) — A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in t

lownvdPublished 2023-07-21

CVE-2023-3609 CVSS: 7.8 HIGH Published: 2023-07-21T21:15:11.743

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation.

If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the refere

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-3609