cbcvebase.
CVE-2023-6932
published 2023-12-19

CVE-2023-6932: A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be…

high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread. We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.66-1 (bookworm)linux 6.1.66-1 (bookworm)
googlechrome_chrome
linuxkernel>= 2.6.12 < 6.76.7
linuxlinux_kernel< 4.14.3324.14.332
linuxlinux_kernel>= 0 < 5.10.205-25.10.205-2
linuxlinux_kernel>= 0 < 6.1.66-16.1.66-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 5.4.0-170.1885.4.0-170.188
linuxlinux_kernel>= 0 < 5.15.0-92.1025.15.0-92.102
linuxlinux_kernel>= 0 < 4.4.0-251.2854.4.0-251.285
linuxlinux_kernel>= 0 < 4.4.0-250.2844.4.0-250.284
linuxlinux_kernel>= 0 < 4.15.0-222.2334.15.0-222.233
linuxlinux_kernel>= 0 < 4.15.0-221.2324.15.0-221.232
linuxlinux_kernel>= 0 < 5.4.0-172.1905.4.0-172.190
linuxlinux_kernel>= 0 < 5.4.0-170.1885.4.0-170.188
linuxlinux_kernel>= 0 < 5.15.0-97.1075.15.0-97.107
linuxlinux_kernel>= 0 < 5.15.0-94.1045.15.0-94.104
linuxlinux_kernel>= 4.15 < 4.19.3014.19.301
linuxlinux_kernel>= 4.20 < 5.4.2635.4.263
linuxlinux_kernel>= 5.11 < 5.15.1425.15.142
linuxlinux_kernel>= 5.16 < 6.1.666.1.66
linuxlinux_kernel>= 5.5 < 5.10.2035.10.203
linuxlinux_kernel>= 6.2 < 6.6.56.6.5

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH