CVE-2023-1829
Summary
| CVE | CVE-2023-1829 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-12 12:15:00 UTC |
| Updated | 2023-10-05 14:52:00 UTC |
| Description | A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root.
We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Linux |
Linux Kernel |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
Mailing List, Patch |
| [SECURITY] [DLA 3403-1] linux security update |
MISC |
lists.debian.org |
|
| [SECURITY] [DLA 3404-1] linux-5.10 security update |
MISC |
lists.debian.org |
|
| CVE-2023-1829 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
MISC |
security.netapp.com |
|
| ???????? |
MISC |
kernel.dance |
Patch |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160859 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-4517)
- 181765 Debian Security Update for linux-5.10 (DLA 3404-1)
- 181768 Debian Security Update for linux (DLA 3403-1)
- 182906 Debian Security Update for linux (CVE-2023-1829)
- 199298 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6033-1)
- 199306 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6043-1)
- 199307 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6044-1)
- 199309 Ubuntu Security Notification for Linux kernel Vulnerability (USN-6047-1)
- 199316 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6051-1)
- 199329 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6070-1)
- 199330 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6072-1)
- 199331 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerability (USN-6069-1)
- 199334 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6071-1)
- 199356 Ubuntu Security Notification for Linux kernel (BlueField) Vulnerabilities (USN-6093-1)
- 199385 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6134-1)
- 199389 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6133-1)
- 199465 Ubuntu Security Notification for Linux kernel (Xilinx ZynqMP) Vulnerabilities (USN-6222-1)
- 199507 Ubuntu Security Notification for Linux kernel Vulnerability (USN-6058-1)
- 199562 Ubuntu Security Notification for Linux kernel Vulnerability (USN-6052-1)
- 199572 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6045-1)
- 199614 Ubuntu Security Notification for Linux kernel (IoT) Vulnerabilities (USN-6256-1)
- 241926 Red Hat Update for kernel (RHSA-2023:4515)
- 241927 Red Hat Update for kernel-rt (RHSA-2023:4541)
- 241929 Red Hat Update for kpatch-patch (RHSA-2023:4516)
- 241934 Red Hat Update for kpatch-patch (RHSA-2023:4531)
- 241936 Red Hat Update for kernel (RHSA-2023:4517)
- 242496 Red Hat Update for kpatch-patch (RHSA-2023:7417)
- 242500 Red Hat Update for kernel-rt (RHSA-2023:7431)
- 242504 Red Hat Update for kernel (RHSA-2023:7434)
- 355138 Amazon Linux Security Advisory for kernel : ALAS-2023-138
- 355288 Amazon Linux Security Advisory for kernel : ALAS-2023-138
- 355291 Amazon Linux Security Advisory for kernel : ALAS-2023-138
- 355297 Amazon Linux Security Advisory for kernel : ALAS-2023-138
- 355301 Amazon Linux Security Advisory for kernel : ALAS-2023-138
- 355305 Amazon Linux Security Advisory for kernel : ALAS-2023-138
- 355307 Amazon Linux Security Advisory for kernel : ALAS-2023-138
- 355314 Amazon Linux Security Advisory for kernel : ALAS2023-2023-138
- 378701 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0030)
- 378710 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0079)
- 379043 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0136)
- 673321 EulerOS Security Update for kernel (EulerOS-SA-2024-1337)
- 673547 EulerOS Security Update for kernel (EulerOS-SA-2024-1315)
- 673657 EulerOS Security Update for kernel (EulerOS-SA-2024-1122)
- 673714 EulerOS Security Update for kernel (EulerOS-SA-2024-1196)
- 673902 EulerOS Security Update for kernel (EulerOS-SA-2024-1176)
- 673995 EulerOS Security Update for kernel (EulerOS-SA-2024-1275)
- 674024 EulerOS Security Update for kernel (EulerOS-SA-2024-1107)
- 754920 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 0 for SLE 15 SP5) (SUSE-SU-2023:3772-1)
- 754921 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 39 for SLE 15 SP1) (SUSE-SU-2023:3768-1)
- 754922 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 1 for SLE 15 SP5) (SUSE-SU-2023:3784-1)
- 754923 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 6 for SLE 15 SP4) (SUSE-SU-2023:3783-1)
- 754924 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 37 for SLE 15 SP1) (SUSE-SU-2023:3786-1)
- 754927 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 31 for SLE 15 SP2) (SUSE-SU-2023:3788-1)
- 754939 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 30 for SLE 15 SP2) (SUSE-SU-2023:3812-1)
- 754940 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 43 for SLE 15 SP1) (SUSE-SU-2023:3811-1)
- 754941 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 42 for SLE 15 SP1) (SUSE-SU-2023:3809-1)
- 754947 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 33 for SLE 15 SP2) (SUSE-SU-2023:3844-1)
- 754948 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 40 for SLE 15 SP1) (SUSE-SU-2023:3838-1)
- 754976 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 36 for SLE 15 SP2) (SUSE-SU-2023:3846-1)
- 754990 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 23 for SLE 15 SP3) (SUSE-SU-2023:3892-1)
- 754991 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 39 for SLE 15 SP2) (SUSE-SU-2023:3891-1)
- 754992 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 38 for SLE 15 SP2) (SUSE-SU-2023:3889-1)
- 754993 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 32 for SLE 15 SP2) (SUSE-SU-2023:3893-1)
- 755004 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 13 for SLE 15 SP4) (SUSE-SU-2023:3922-1)
- 755005 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 35 for SLE 15 SP3) (SUSE-SU-2023:3912-1)
- 755006 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 26 for SLE 15 SP3) (SUSE-SU-2023:3928-1)
- 755105 SUSE Enterprise Linux Security Update for suse-module-tools (SUSE-SU-2023:4097-1)
- 755123 SUSE Enterprise Linux Security Update for suse-module-tools (SUSE-SU-2023:4136-1)
- 755124 SUSE Enterprise Linux Security Update for suse-module-tools (SUSE-SU-2023:4135-1)
- 755128 SUSE Enterprise Linux Security Update for suse-module-tools (SUSE-SU-2023:4160-1)
- 755129 SUSE Enterprise Linux Security Update for suse-module-tools (SUSE-SU-2023:4159-1)
- 755130 SUSE Enterprise Linux Security Update for suse-module-tools (SUSE-SU-2023:4158-1)
- 755178 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 36 for SLE 15 SP3) (SUSE-SU-2023:4261-1)
- 755182 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 40 for SLE 15 SP2) (SUSE-SU-2023:4243-1)
- 755183 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 41 for SLE 15 SP2) (SUSE-SU-2023:4264-1)
- 755193 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 44 for SLE 15 SP1) (SUSE-SU-2023:4280-1)
- 755400 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 45 for SLE 15 SP1) (SUSE-SU-2023:4774-1)
- 755411 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 42 for SLE 15 SP2) (SUSE-SU-2023:4804-1)
- 755421 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 38 for SLE 15 SP3) (SUSE-SU-2023:4845-1)
- 755716 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 47 for SLE 15 SP1) (SUSE-SU-2024:0377-1)
- 755717 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 43 for SLE 15 SP2) (SUSE-SU-2024:0376-1)
- 755719 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 40 for SLE 15 SP3) (SUSE-SU-2024:0394-1)
- 755720 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 39 for SLE 15 SP3) (SUSE-SU-2024:0393-1)
- 755723 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 44 for SLE 15 SP2) (SUSE-SU-2024:0410-1)
- 755867 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 41 for SLE 15 SP3) (SUSE-SU-2024:0695-1)
- 756135 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 42 for SLE 15 SP3) (SUSE-SU-2024:1276-1)
- 906833 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (26171-1)
- 906871 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (26169-1)
- 941227 AlmaLinux Security Update for kernel (ALSA-2023:4517)
- 941228 AlmaLinux Security Update for kernel-rt (ALSA-2023:4541)
- 961032 Rocky Linux Security Update for kernel (RLSA-2023:4517)
- 961046 Rocky Linux Security Update for kernel-rt (RLSA-2023:4541)