CVE-2023-6270
Description
A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on struct net_device
, and a use-after-free can be triggered by racing between the free on the struct and the access through the skbtxq
global queue. This could lead to a denial of service condition or potential code execution.
- CVSS Version 3.1
nvd
CVE ID: CVE-2023-6270
Base Score: 7.0
Base Severity: HIGH
Vector String:CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.0
redhat
CVE ID: CVE-2023-6270
Base Score: 7.0
Base Severity: HIGH
Vector String:CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.0