cbcvebase.
CVE-2023-6270
published 2024-01-04

CVE-2023-6270: A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct…

PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.41%
33.2th percentile
A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
fedoraprojectfedora
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 1a54aa506b3b2f31496731039e49778f54eee881 < a786265aecf39015418e4f930cc1c14603a01490a786265aecf39015418e4f930cc1c14603a01490
linuxlinux>= 4.19.311 < 4.19.3234.19.323
linuxlinux>= 5.10.214 < 5.10.2275.10.227
linuxlinux>= 5.15.153 < 5.15.1685.15.168
linuxlinux>= 5.4.273 < 5.4.2855.4.285
linuxlinux>= 6.1.83 < 6.1.1136.1.113
linuxlinux>= 6.6.23 < 6.6.556.6.55
linuxlinux>= 6.7.11 < 6.86.8
linuxlinux>= 6.8.2 < 6.96.9
linuxlinux>= 74ca3ef68d2f449bc848c0a814cefc487bf755fa < bc2cbf7525ac288e07d465f5a1d8cb8fb9599254bc2cbf7525ac288e07d465f5a1d8cb8fb9599254
linuxlinux>= 7dd09fa80b0765ce68bfae92f4e2f395ccf0fba4 < 07b418d50ccbbca7e5d87a3a0d41d436cefebf7907b418d50ccbbca7e5d87a3a0d41d436cefebf79
linuxlinux>= ad80c34944d7175fa1f5c7a55066020002921a99 < 12f7b89dd72b25da4eeaa22097877963cad6418e12f7b89dd72b25da4eeaa22097877963cad6418e
linuxlinux>= eb48680b0255a9e8a9bdc93d6a55b11c31262e62 < acc5103a0a8c200a52af7d732c36a8477436a3d3acc5103a0a8c200a52af7d732c36a8477436a3d3
linuxlinux>= f98364e926626c678fb4b9004b75cacf92ff0662 < 89d9a69ae0c667e4d9d028028e2dcc837bae626f89d9a69ae0c667e4d9d028028e2dcc837bae626f
linuxlinux>= f98364e926626c678fb4b9004b75cacf92ff0662 < 8253a60c89ec35c8f36fb2cc08cdf854c7a3eb588253a60c89ec35c8f36fb2cc08cdf854c7a3eb58
linuxlinux>= f98364e926626c678fb4b9004b75cacf92ff0662 < 6d6e54fc71ad1ab0a87047fd9c211e75d86084a36d6e54fc71ad1ab0a87047fd9c211e75d86084a3

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.