CVE-2023-1829

    Dashboard / Vulnerabilities / CVE-2023-1829

    CVE-2023-1829

    Published: 12 Apr 2023Last Modified: 15 Jul 2026

    Summary: Use-after-free in tcindex (traffic control index filter) in the Linux Kernel

    Details: A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root. We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 19f949f52599ba7c3f67a5897ac6be14bfcb1200
    Fixed -None

    Affected versions

    v6.2-rc6

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-1829 | CVE-DB