CVE-2023-4921

    Dashboard / Vulnerabilities / CVE-2023-4921

    CVE-2023-4921

    Published: 12 Sept 2023Last Modified: 12 Aug 2026

    Summary: Use-after-free in Linux kernel's net/sched: sch_qfq component

    Details: A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. When the plug qdisc is used as a class of the qfq qdisc, sending network packets triggers use-after-free in qfq_dequeue() due to the incorrect .peek handler of sch_plug and lack of error checking in agg_dequeue(). We recommend upgrading past commit 8fc134fee27f2263988ae38920bc03da416b03d8.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 19f949f52599ba7c3f67a5897ac6be14bfcb1200

    Affected versions

    v6.6-rc1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-4921 | CVE-DB