CVE-2023-4921
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Sep 12, 2023
Updated: Jan 11, 2024
CWE ID 416
Summary
CVE-2023-4921 is a local privilege escalation vulnerability affecting the Linux kernel's net/sched: sch_qfq component. This issue arises due to a use-after-free condition in the qfq_dequeue() function, which can be triggered when processing network packets. The root cause is the incorrect .peek handler in sch_plug and insufficient error checking in agg_dequeue(). To mitigate this vulnerability, it is recommended to upgrade the Linux kernel to a version past commit 8fc134fee27f2263988ae38920bc03da416b03d8.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.