There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not require any privilege.

There is a use-after-free bug of icsk_ulp_data of a struct inet_connection_sock.

When CONFIG_TLS is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable.

The setsockopt TCP_ULP operation does not require any privilege.

We recommend upgrading past commit 2c02d41d71f90a5168391b6a5f2954112ba2307c
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
Title Use-after-free vulnerability in the Linux Kernel Use-after-free vulnerability in the Linux Kernel

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2025-02-13T16:38:58.993Z

Reserved: 2023-01-24T09:47:24.966Z

Link: CVE-2023-0461

cve-icon Vulnrichment

Updated: 2024-08-02T05:10:56.165Z

cve-icon NVD

Status : Modified

Published: 2023-02-28T15:15:11.550

Modified: 2024-11-21T07:37:13.430

Link: CVE-2023-0461

cve-icon Redhat

Severity : Important

Publid Date: 2023-02-23T00:00:00Z

Links: CVE-2023-0461 - Bugzilla

cve-icon OpenCVE Enrichment

No data.