Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcfextsexec()' is called with the destroyed tcf_ext. A local attacker user can use this vulnerability to elevate its privileges to root. This issue affects Linux Kernel: from 4.14 before git commit ee059170b1f7e94e55fa6cadee544e176a6e59c2.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-1281.json"
[
{
"digest": {
"function_hash": "334519611757451062646832656916534789711",
"length": 3803.0
},
"signature_version": "v1",
"target": {
"file": "net/sched/cls_tcindex.c",
"function": "tcindex_set_parms"
},
"signature_type": "Function",
"id": "CVE-2023-1281-6967cb0f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@ee059170b1f7e94e55fa6cadee544e176a6e59c2",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"106726959524410161074059465341348582030",
"53913627472378761692504529599443150708",
"60170519165706428483750432344635609762",
"126893275607912530075725017232162792108",
"312138549585818393203623772737492564364",
"54291067994685208118429077468720676624",
"149814317999386509890839012748307634573",
"259434757587052540717839120908142262435",
"283235570742025185625194300562276398296",
"25841449932404129724610478872911493846",
"53668400235300457148034367018888076425",
"72504140927466995198570603084150364536",
"130041778226414487121633006505271345565",
"110306982607864598251684365538121866142",
"271658460938297260634318367297978718033",
"333282269755591570342549332393484639251",
"74818626647526360007366965143585370889",
"248407809600343301585187534315585741497",
"251455037606805199624792476559186954141"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "net/sched/cls_tcindex.c"
},
"signature_type": "Line",
"id": "CVE-2023-1281-b7d8d8a4",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@ee059170b1f7e94e55fa6cadee544e176a6e59c2",
"deprecated": false
}
]