Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prhq-c3gx-jhwg

Опубликовано: 04 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on struct net_device, and a use-after-free can be triggered by racing between the free on the struct and the access through the skbtxq global queue. This could lead to a denial of service condition or potential code execution.

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on struct net_device, and a use-after-free can be triggered by racing between the free on the struct and the access through the skbtxq global queue. This could lead to a denial of service condition or potential code execution.

EPSS

Процентиль: 6%
0.00023
Низкий

7 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7
ubuntu
около 2 лет назад

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.

CVSS3: 7
redhat
около 2 лет назад

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.

CVSS3: 7
nvd
около 2 лет назад

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.

msrc
5 месяцев назад

Kernel: aoe: improper reference count leads to use-after-free vulnerability

CVSS3: 7
debian
около 2 лет назад

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux ke ...

EPSS

Процентиль: 6%
0.00023
Низкий

7 High

CVSS3

Дефекты

CWE-416