Back

HIGH

Use-after-free in Linux kernel's net/sched: cls_fw component

Published Jul 21, 2023

Description

A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation.

If tcf_change_indev() fails, fw_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.

We recommend upgrading past commit 0323bce598eea038714f941ce2b22541c46d488f.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, prevent module cls_fw from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Jul 21, 2023
Updated Mar 5, 2025
Reserved Jul 19, 2023
CISA Vulnrichment
Updated Mar 5, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 6, 2023
ENISA EUVD
Assigner Google
Published Jul 21, 2023
Updated Mar 5, 2025
Exploited since n/a
EUVD-2023-44409