Use-after-free in Linux kernel's net/sched: cls_fw component
Published Jul 21, 2023
7.8
HIGHCVSS 3.1
EPSS 0.51%
Description
A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation.
If tcf_change_indev() fails, fw_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.
We recommend upgrading past commit 0323bce598eea038714f941ce2b22541c46d488f.
Affected products
-
- Version 2.6StatusaffectedConstraints<6.5
- Version
Configuration 1
- ≥ 2.6.12 · < 4.14.322
- ≥ 4.15 · < 4.19.291
- ≥ 4.20 · < 5.4.251
- ≥ 5.5 · < 5.10.188
- ≥ 5.11 · < 5.15.121
- ≥ 5.16 · < 6.1.40
- ≥ 6.2 · < 6.4.5
- 6.5
Configuration 2
- 10.0
- 11.0
- 12.0
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support
kernel-0:2.6.32-754.53.1.el6
Fixed · RHSA-2024:1831
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.105.1.el7
Fixed · RHSA-2023:7423
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.105.1.rt56.1256.el7
Fixed · RHSA-2023:7424
Red Hat Enterprise Linux 7
kpatch-patch
Fixed · RHSA-2023:7419
Red Hat Enterprise Linux 7.6 Advanced Update Support
kernel-0:3.10.0-957.108.1.el7
Fixed · RHSA-2023:7294
Red Hat Enterprise Linux 7.7 Advanced Update Support
kernel-0:3.10.0-1062.82.1.el7
Fixed · RHSA-2024:0262
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.27.1.el8_8
Fixed · RHSA-2023:5244
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-477.27.1.rt7.290.el8_8
Fixed · RHSA-2023:5255
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2023:5221
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kernel-0:4.18.0-147.94.1.el8_1
Fixed · RHSA-2023:6813
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:6799
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.119.1.el8_2
Fixed · RHSA-2023:7434
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-0:4.18.0-193.119.1.el8_2
Fixed · RHSA-2023:7434
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-rt-0:4.18.0-193.119.1.rt13.170.el8_2
Fixed · RHSA-2023:7431
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kernel-0:4.18.0-193.119.1.el8_2
Fixed · RHSA-2023:7434
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:7417
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.108.1.el8_4
Fixed · RHSA-2023:5628
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-0:4.18.0-305.108.1.el8_4
Fixed · RHSA-2023:5628
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-rt-0:4.18.0-305.108.1.rt7.183.el8_4
Fixed · RHSA-2023:5794
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kernel-0:4.18.0-305.108.1.el8_4
Fixed · RHSA-2023:5628
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:5775
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.80.1.el8_6
Fixed · RHSA-2023:7398
Red Hat Enterprise Linux 8.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:7410
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.30.1.el9_2
Fixed · RHSA-2023:5069
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.30.1.el9_2
Fixed · RHSA-2023:5069
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-284.30.1.rt14.315.el9_2
Fixed · RHSA-2023:5091
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2023:5093
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.80.1.el9_0
Fixed · RHSA-2023:7382
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.80.1.rt21.151.el9_0
Fixed · RHSA-2023:7389
Red Hat Enterprise Linux 9.0 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:7411
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.80.1.el8_6
Fixed · RHSA-2023:7398
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support | kernel-0:2.6.32-754.53.1.el6 | Fixed | RHSA-2024:1831 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.105.1.el7 | Fixed | RHSA-2023:7423 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.105.1.rt56.1256.el7 | Fixed | RHSA-2023:7424 |
| Red Hat Enterprise Linux 7 | kpatch-patch | Fixed | RHSA-2023:7419 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | kernel-0:3.10.0-957.108.1.el7 | Fixed | RHSA-2023:7294 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | kernel-0:3.10.0-1062.82.1.el7 | Fixed | RHSA-2024:0262 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.27.1.el8_8 | Fixed | RHSA-2023:5244 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-477.27.1.rt7.290.el8_8 | Fixed | RHSA-2023:5255 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2023:5221 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kernel-0:4.18.0-147.94.1.el8_1 | Fixed | RHSA-2023:6813 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:6799 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.119.1.el8_2 | Fixed | RHSA-2023:7434 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-0:4.18.0-193.119.1.el8_2 | Fixed | RHSA-2023:7434 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-rt-0:4.18.0-193.119.1.rt13.170.el8_2 | Fixed | RHSA-2023:7431 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kernel-0:4.18.0-193.119.1.el8_2 | Fixed | RHSA-2023:7434 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:7417 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.108.1.el8_4 | Fixed | RHSA-2023:5628 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-0:4.18.0-305.108.1.el8_4 | Fixed | RHSA-2023:5628 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-rt-0:4.18.0-305.108.1.rt7.183.el8_4 | Fixed | RHSA-2023:5794 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kernel-0:4.18.0-305.108.1.el8_4 | Fixed | RHSA-2023:5628 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:5775 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.80.1.el8_6 | Fixed | RHSA-2023:7398 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:7410 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.30.1.el9_2 | Fixed | RHSA-2023:5069 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.30.1.el9_2 | Fixed | RHSA-2023:5069 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-284.30.1.rt14.315.el9_2 | Fixed | RHSA-2023:5091 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2023:5093 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.80.1.el9_0 | Fixed | RHSA-2023:7382 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.80.1.rt21.151.el9_0 | Fixed | RHSA-2023:7389 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:7411 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.80.1.el8_6 | Fixed | RHSA-2023:7398 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, prevent module cls_fw from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
References (14)
- http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSN-0098-1.html Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/175963/Kernel-Live-Patch-Security-Notice-LSN-0099-1.html Third Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2023-3776 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2225097 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44409 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=0323bce598eea038714f941ce2b22541c46d488f patchMailing ListVendor Advisory
- https://kernel.dance/0323bce598eea038714f941ce2b22541c46d488f PatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-3776
- https://security.netapp.com/advisory/ntap-20240202-0003/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-3776
- https://www.debian.org/security/2023/dsa-5480 Third Party Advisory
- https://www.debian.org/security/2023/dsa-5492 Third Party Advisory
Change history (0)
No recorded changes yet.