UBUNTU-CVE-2023-6270
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-6270
UBUNTU-CVE-2023-6270
Summary:
Details: A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.
References: https://ubuntu.com/security/CVE-2023-6270, https://www.zerodayinitiative.com/advisories/ZDI-CAN-22236, https://access.redhat.com/security/cve/CVE-2023-6270, https://www.cve.org/CVERecord?id=CVE-2023-6270, https://ubuntu.com/security/notices/USN-6816-1, https://ubuntu.com/security/notices/USN-6817-1, https://ubuntu.com/security/notices/USN-6820-1, https://ubuntu.com/security/notices/USN-6821-1, https://ubuntu.com/security/notices/USN-6821-2, https://ubuntu.com/security/notices/USN-6817-2, https://ubuntu.com/security/notices/USN-6828-1, https://ubuntu.com/security/notices/USN-6820-2, https://ubuntu.com/security/notices/USN-6821-3, https://ubuntu.com/security/notices/USN-6817-3, https://ubuntu.com/security/notices/USN-6821-4, https://ubuntu.com/security/notices/USN-6865-1, https://ubuntu.com/security/notices/USN-6866-1, https://ubuntu.com/security/notices/USN-6871-1, https://ubuntu.com/security/notices/USN-6878-1, https://ubuntu.com/security/notices/USN-6866-2, https://ubuntu.com/security/notices/USN-6866-3, https://ubuntu.com/security/notices/USN-6892-1, https://ubuntu.com/security/notices/USN-6895-1, https://ubuntu.com/security/notices/USN-6896-1, https://ubuntu.com/security/notices/USN-6895-2, https://ubuntu.com/security/notices/USN-6896-2, https://ubuntu.com/security/notices/USN-6900-1, https://ubuntu.com/security/notices/USN-6896-3, https://ubuntu.com/security/notices/USN-6895-3, https://ubuntu.com/security/notices/USN-6896-4, https://ubuntu.com/security/notices/USN-6896-5, https://ubuntu.com/security/notices/USN-6919-1, https://ubuntu.com/security/notices/USN-6895-4
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
