UBUNTU-CVE-2023-1829
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-1829
UBUNTU-CVE-2023-1829
Summary:
Details: A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root. We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ .
References: https://ubuntu.com/security/CVE-2023-1829, https://www.openwall.com/lists/oss-security/2023/04/11/3, https://ubuntu.com/security/notices/USN-6033-1, https://ubuntu.com/security/notices/USN-6043-1, https://ubuntu.com/security/notices/USN-6044-1, https://ubuntu.com/security/notices/USN-6045-1, https://ubuntu.com/security/notices/USN-6047-1, https://ubuntu.com/security/notices/USN-6051-1, https://ubuntu.com/security/notices/USN-6052-1, https://ubuntu.com/security/notices/USN-6058-1, https://ubuntu.com/security/notices/USN-6069-1, https://ubuntu.com/security/notices/USN-6070-1, https://ubuntu.com/security/notices/USN-6071-1, https://ubuntu.com/security/notices/USN-6072-1, https://ubuntu.com/security/notices/USN-6093-1, https://ubuntu.com/security/notices/USN-6107-1, https://ubuntu.com/security/notices/USN-6133-1, https://ubuntu.com/security/notices/USN-6134-1, https://ubuntu.com/security/notices/USN-6222-1, https://ubuntu.com/security/notices/USN-6256-1, https://www.cve.org/CVERecord?id=CVE-2023-1829
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
