Vulnerability identifier: #VU113376
Vulnerability risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-416
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the qfq_change_class(), qfq_delete_class(), qfq_dump_class() and qfq_dump_class_stats() functions in net/sched/sch_qfq.c. A local user can escalate privileges on the system.
Mitigation
Install update from vendor's repository.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/466e10194ab81caa2ee6a332d33ba16bcceeeba6
https://git.kernel.org/stable/c/5e28d5a3f774f118896aec17a3a20a9c5c9dfc64
https://git.kernel.org/stable/c/a6d735100f602c830c16d69fb6d780eebd8c9ae1
https://git.kernel.org/stable/c/c000a3a330d97f6c073ace5aa5faf94b9adb4b79
https://git.kernel.org/stable/c/fbe48f06e64134dfeafa89ad23387f66ebca3527
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?