UBUNTU-CVE-2023-4921
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-4921
UBUNTU-CVE-2023-4921
Summary:
Details: A use-after-free vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. When the plug qdisc is used as a class of the qfq qdisc, sending network packets triggers use-after-free in qfq_dequeue() due to the incorrect .peek handler of sch_plug and lack of error checking in agg_dequeue(). We recommend upgrading past commit 8fc134fee27f2263988ae38920bc03da416b03d8.
References: https://ubuntu.com/security/CVE-2023-4921, https://lore.kernel.org/all/[email protected]/, https://ubuntu.com/security/notices/USN-6439-1, https://ubuntu.com/security/notices/USN-6440-1, https://ubuntu.com/security/notices/USN-6441-1, https://ubuntu.com/security/notices/USN-6442-1, https://ubuntu.com/security/notices/USN-6444-1, https://ubuntu.com/security/notices/USN-6445-1, https://ubuntu.com/security/notices/USN-6446-1, https://ubuntu.com/security/notices/USN-6440-2, https://ubuntu.com/security/notices/USN-6439-2, https://ubuntu.com/security/notices/USN-6441-2, https://ubuntu.com/security/notices/USN-6444-2, https://ubuntu.com/security/notices/USN-6445-2, https://ubuntu.com/security/notices/USN-6446-2, https://ubuntu.com/security/notices/USN-6440-3, https://ubuntu.com/security/notices/USN-6446-3, https://ubuntu.com/security/notices/USN-6454-1, https://ubuntu.com/security/notices/USN-6441-3, https://ubuntu.com/security/notices/USN-6454-2, https://ubuntu.com/security/notices/USN-6461-1, https://ubuntu.com/security/notices/USN-6466-1, https://ubuntu.com/security/notices/USN-6454-3, https://ubuntu.com/security/notices/USN-6454-4, https://ubuntu.com/security/notices/USN-6479-1, https://ubuntu.com/security/notices/USN-6699-1, https://www.cve.org/CVERecord?id=CVE-2023-4921
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
