Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prhq-c3gx-jhwg

Опубликовано: 04 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on struct net_device, and a use-after-free can be triggered by racing between the free on the struct and the access through the skbtxq global queue. This could lead to a denial of service condition or potential code execution.

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on struct net_device, and a use-after-free can be triggered by racing between the free on the struct and the access through the skbtxq global queue. This could lead to a denial of service condition or potential code execution.

EPSS

Процентиль: 34%
0.0041
Низкий

7 High

CVSS3

Дефекты

CWE-416
CWE-911

Связанные уязвимости

CVSS3: 7
ubuntu
больше 2 лет назад

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.

CVSS3: 7
redhat
больше 2 лет назад

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.

CVSS3: 7
nvd
больше 2 лет назад

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.

msrc
12 месяцев назад

Kernel: aoe: improper reference count leads to use-after-free vulnerability

CVSS3: 7
debian
больше 2 лет назад

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux ke ...

EPSS

Процентиль: 34%
0.0041
Низкий

7 High

CVSS3

Дефекты

CWE-416
CWE-911