A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmdcfgpkts() function improperly updates the refcnt on struct net_device, and a use-after-free can be triggered by racing between the free on the struct and the access through the skbtxq global queue. This could lead to a denial of service condition or potential code execution.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-6270.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "39"
}
]
}
]