A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. When the plug qdisc is used as a class of the qfq qdisc, sending network packets triggers use-after-free in qfq_dequeue() due to the incorrect .peek handler of sch_plug and lack of error checking in agg_dequeue(). We recommend upgrading past commit 8fc134fee27f2263988ae38920bc03da416b03d8.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2023-09-12T19:45:19.367Z

Updated: 2024-08-02T07:44:52.210Z

Reserved: 2023-09-12T19:22:10.389Z

Link: CVE-2023-4921

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-09-12T20:15:10.573

Modified: 2024-08-26T16:06:55.377

Link: CVE-2023-4921

cve-icon Redhat

Severity : Important

Publid Date: 2023-09-05T00:00:00Z

Links: CVE-2023-4921 - Bugzilla