A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation.
A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.
We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.
References
Configurations
History
21 Nov 2024, 08:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/177029/Kernel-Live-Patch-Security-Notice-LSN-0100-1.html - | |
References | () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=e2b706c691905fe78468c361aaabc719d0a496f1 - Mailing List, Patch | |
References | () https://kernel.dance/e2b706c691905fe78468c361aaabc719d0a496f1 - Patch | |
References | () https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html - | |
References | () https://lists.debian.org/debian-lts-announce/2024/01/msg00005.html - | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
08 Feb 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Jan 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
11 Jan 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 Dec 2023, 17:00
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-416 | |
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
References | () https://kernel.dance/e2b706c691905fe78468c361aaabc719d0a496f1 - Patch | |
References | () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=e2b706c691905fe78468c361aaabc719d0a496f1 - Mailing List, Patch | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.0 |
First Time |
Linux
Linux linux Kernel |
19 Dec 2023, 14:49
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-19 14:15
Updated : 2024-11-21 08:44
NVD link : CVE-2023-6932
Mitre link : CVE-2023-6932
CVE.ORG link : CVE-2023-6932
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free