← Back

CVE-2023-4623

nvd nist
Published: Sep 6, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A use-after-free vulnerability in the Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component can be exploited to achieve local privilege escalation. If a class with a link-sharing curve (i.e. with the HFSC_FSC flag set) has a parent without a link-sharing curve, then init_vf() will call vttree_insert() on the parent, but vttree_remove() will be skipped in update_vf(). This leaves a dangling pointer that can cause a use-after-free. We recommend upgrading past commit b3d26c5702c7d6c45456326e56d2ccf3f103e60f.

Affected (9)

1 product
Linux Kernel
1 product
Debian Linux
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 2.6.12 to 4.14.327
From 4.15 to 4.19.295
From 4.20 to 5.4.257
From 5.11 to 5.15.132
From 5.16 to 6.1.53
From 5.5 to 5.10.195
From 6.2 to 6.4.16
From 6.5 to 6.5.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0

References (10)

Source: cve-coordination@google.com
Third Party AdvisoryVDB Entry
Source: cve-coordination@google.com
Issue TrackingMailing ListPatchVendor Advisory
Source: cve-coordination@google.com
PatchVendor Advisory
Source: cve-coordination@google.com
Mailing ListThird Party Advisory
Source: cve-coordination@google.com
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.