Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-53733

Опубликовано: 24 окт. 2025
Источник: redhat
CVSS3: 4.4

Описание

In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_u32: Undo tcf_bind_filter if u32_replace_hw_knode When u32_replace_hw_knode fails, we need to undo the tcf_bind_filter operation done at u32_set_parms.

Отчет

Fix ensures cls_u32 properly unbinds a filter from its class if u32_replace_hw_knode() fails during HW offload. Without the unbind, a dangling bind/reference could persist, leading to inconsistent classifier state, potential reference leaks, or kernel crashes on later updates/removals. Exploitation requires local CAP_NET_ADMIN to manipulate tc u32 rules.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelFix deferred
Red Hat Enterprise Linux 7kernel-rtFix deferred
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-664
https://bugzilla.redhat.com/show_bug.cgi?id=2406197kernel: net: sched: cls_u32: Undo tcf_bind_filter if u32_replace_hw_knode

4.4 Medium

CVSS3

Связанные уязвимости

ubuntu
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_u32: Undo tcf_bind_filter if u32_replace_hw_knode When u32_replace_hw_knode fails, we need to undo the tcf_bind_filter operation done at u32_set_parms.

nvd
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_u32: Undo tcf_bind_filter if u32_replace_hw_knode When u32_replace_hw_knode fails, we need to undo the tcf_bind_filter operation done at u32_set_parms.

debian
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: n ...

github
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_u32: Undo tcf_bind_filter if u32_replace_hw_knode When u32_replace_hw_knode fails, we need to undo the tcf_bind_filter operation done at u32_set_parms.

CVSS3: 7
fstec
около 3 лет назад

Уязвимость модуля net/sched/cls_u32.c ядра операционных систем Linux, позволяющая нарушителю вызвать отказ в обслуживании

4.4 Medium

CVSS3

Уязвимость CVE-2023-53733