A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation.
When the plug qdisc is used as a class of the qfq qdisc, sending network packets triggers use-after-free in qfq_dequeue() due to the incorrect .peek handler of sch_plug and lack of error checking in agg_dequeue().
We recommend upgrading past commit 8fc134fee27f2263988ae38920bc03da416b03d8.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Google
Published: 2023-09-12T19:45:19.367Z
Updated: 2024-08-02T07:44:52.210Z
Reserved: 2023-09-12T19:22:10.389Z
Link: CVE-2023-4921
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-09-12T20:15:10.573
Modified: 2024-11-21T08:36:16.270
Link: CVE-2023-4921
Redhat