Description
In the Linux kernel, the following vulnerability has been resolved: sch/netem: fix use after free in netem_dequeue If netem_dequeue() enqueues packet to inner qdisc and that qdisc returns __NET_XMIT_STOLEN. The packet is dropped but qdisc_tree_reduce_backlog() is not called to update the parent's q.qlen, leading to the similar use-after-free as Commit e04991a48dbaf382 ("netem: fix return value if duplicate enqueue fails") Commands to trigger KASAN UaF: ip link add type dummy ip link set lo up ip link set dummy0 up tc qdisc add dev lo parent root handle 1: drr tc filter add dev lo parent 1: basic classid 1:1 tc class add dev lo classid 1:1 drr tc qdisc add dev lo parent 1:1 handle 2: netem tc qdisc add dev lo parent 2: handle 3: drr tc filter add dev lo parent 3: basic classid 3:1 action mirred egress redirect dev dummy0 tc class add dev lo classid 3:1 drr ping -c1 -W0.01 localhost # Trigger bug tc class del dev lo classid 1:1 tc class add dev lo classid 1:1 drr ping -c1 -W0.01 localhost # UaF
Details
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| linux | — | 6.8.0-49.49 |
| linux-allwinner-5.19 | — | — |
| linux-aws | — | 6.8.0-1019.21 |
| linux-aws-5.0 | — | — |
| linux-aws-5.11 | — | — |
| linux-aws-5.13 | — | — |
| linux-aws-5.15 | — | 5.15.0-1072.78~20.04.1 |
| linux-aws-5.19 | — | — |
| linux-aws-5.3 | — | — |
| linux-aws-5.4 | — | 5.4.0-1135.145~18.04.1 |
| linux-aws-5.8 | — | — |
| linux-aws-6.2 | — | — |
| linux-aws-6.5 | — | — |
| linux-aws-6.8 | — | 6.8.0-1019.21~22.04.1 |
| linux-aws-fips | — | 5.15.0-1072.78+fips1 |
| linux-aws-hwe | — | 4.15.0-1175.188~16.04.1 |
| linux-azure | — | 6.8.0-1018.21 |
| linux-azure-4.15 | — | 4.15.0-1183.198 |
| linux-azure-5.11 | — | — |
| linux-azure-5.13 | — | — |
| linux-azure-5.15 | — | 5.15.0-1078.87~20.04.1 |
| linux-azure-5.19 | — | — |
| linux-azure-5.3 | — | — |
| linux-azure-5.4 | — | 5.4.0-1140.147~18.04.1 |
| linux-azure-5.8 | — | — |
| linux-azure-6.2 | — | — |
| linux-azure-6.5 | — | — |
| linux-azure-6.8 | — | 6.8.0-1018.21~22.04.1 |
| linux-azure-edge | — | — |
| linux-azure-fde | — | — |
| linux-azure-fde-5.19 | — | — |
| linux-azure-fde-6.2 | — | — |
| linux-azure-fips | — | 5.15.0-1075.84+fips1 |
| linux-bluefield | — | — |
| linux-fips | — | 6.8.0-78.78+fips1 |
| linux-gcp | — | 6.8.0-1018.20 |
| linux-gcp-4.15 | — | 4.15.0-1168.185 |
| linux-gcp-5.11 | — | — |
| linux-gcp-5.13 | — | — |
| linux-gcp-5.15 | — | 5.15.0-1071.79~20.04.1 |
| linux-gcp-5.19 | — | — |
| linux-gcp-5.3 | — | — |
| linux-gcp-5.4 | — | 5.4.0-1139.148~18.04.1 |
| linux-gcp-5.8 | — | — |
| linux-gcp-6.2 | — | — |
| linux-gcp-6.5 | — | — |
| linux-gcp-6.8 | — | 6.8.0-1018.20~22.04.1 |
| linux-gcp-fips | — | 5.15.0-1071.79+fips1 |
| linux-gke | — | 6.8.0-1014.18 |
| linux-gke-4.15 | — | — |
| linux-gke-5.15 | — | — |
| linux-gke-5.4 | — | — |
| linux-gkeop | — | 6.8.0-1002.4 |
| linux-gkeop-5.15 | — | 5.15.0-1055.62~20.04.1 |
| linux-gkeop-5.4 | — | — |
| linux-hwe | — | — |
| linux-hwe-5.11 | — | — |
| linux-hwe-5.13 | — | — |
| linux-hwe-5.15 | — | 5.15.0-125.135~20.04.1 |
| linux-hwe-5.19 | — | — |
| linux-hwe-5.4 | — | 5.4.0-200.220~18.04.1 |
| linux-hwe-5.8 | — | — |
| linux-hwe-6.2 | — | — |
| linux-hwe-6.5 | — | — |
| linux-hwe-6.8 | — | 6.8.0-49.49~22.04.1 |
| linux-hwe-edge | — | — |
| linux-ibm | — | 6.8.0-1016.16 |
| linux-ibm-5.15 | — | 5.15.0-1065.68~20.04.1 |
| linux-ibm-5.4 | — | 5.4.0-1082.87~18.04.1 |
| linux-ibm-6.8 | — | 6.8.0-1016.16~22.04.1 |
| linux-intel-5.13 | — | — |
| linux-intel-iot-realtime | — | 5.15.0-1066.68 |
| linux-intel-iotg | — | 5.15.0-1067.73 |
| linux-intel-iotg-5.15 | — | 5.15.0-1067.73~20.04.1 |
| linux-iot | — | 5.4.0-1044.45 |
| linux-kvm | — | 5.15.0-1069.74 |
| linux-lowlatency | — | 6.8.0-49.49.1 |
| linux-lowlatency-hwe-5.15 | — | 5.15.0-125.135~20.04.1 |
| linux-lowlatency-hwe-5.19 | — | — |
| linux-lowlatency-hwe-6.2 | — | — |
| linux-lowlatency-hwe-6.5 | — | — |
| linux-lowlatency-hwe-6.8 | — | 6.8.0-49.49.1~22.04.1 |
| linux-lts-xenial | — | 4.4.0-261.295~14.04.1 |
| linux-nvidia | — | 6.8.0-1018.20 |
| linux-nvidia-6.2 | — | — |
| linux-nvidia-6.5 | — | — |
| linux-nvidia-6.8 | — | 6.8.0-1018.20~22.04.1 |
| linux-nvidia-lowlatency | — | 6.8.0-1018.20.1 |
| linux-nvidia-tegra | — | 5.15.0-1032.32 |
| linux-nvidia-tegra-5.15 | — | 5.15.0-1032.32~20.04.1 |
| linux-nvidia-tegra-igx | — | 5.15.0-1020.20 |
| linux-oem | — | — |
| linux-oem-5.10 | — | — |
| linux-oem-5.13 | — | — |
| linux-oem-5.14 | — | — |
| linux-oem-5.17 | — | — |
| linux-oem-5.6 | — | — |
| linux-oem-6.0 | — | — |
| linux-oem-6.1 | — | — |
| linux-oem-6.5 | — | — |
| linux-oem-6.8 | — | 6.8.0-1017.17 |
| linux-oracle | — | 6.8.0-1016.17 |
| linux-oracle-5.0 | — | — |
| linux-oracle-5.11 | — | — |
| linux-oracle-5.13 | — | — |
| linux-oracle-5.15 | — | 5.15.0-1070.76~20.04.1 |
| linux-oracle-5.3 | — | — |
| linux-oracle-5.4 | — | 5.4.0-1134.143~18.04.1 |
| linux-oracle-5.8 | — | — |
| linux-oracle-6.5 | — | — |
| linux-oracle-6.8 | — | 6.8.0-1016.17~22.04.1 |
| linux-raspi | — | 6.8.0-1015.17 |
| linux-raspi-5.4 | — | 5.4.0-1119.131~18.04.1 |
| linux-raspi-realtime | — | 6.8.0-2014.15 |
| linux-raspi2 | — | — |
| linux-realtime | — | 6.8.1-1012.12 |
| linux-realtime-6.8 | — | 6.8.1-1012.12~22.04.1 |
| linux-riscv | — | 6.8.0-49.49.1 |
| linux-riscv-5.11 | — | — |
| linux-riscv-5.15 | — | 5.15.0-1068.72~20.04.1 |
| linux-riscv-5.19 | — | — |
| linux-riscv-5.8 | — | — |
| linux-riscv-6.5 | — | — |
| linux-riscv-6.8 | — | 6.8.0-49.49.1~22.04.1 |
| linux-starfive-5.19 | — | — |
| linux-starfive-6.2 | — | — |
| linux-starfive-6.5 | — | — |
| linux-xilinx | — | 6.8.0-1017.18 |
| linux-xilinx-zynqmp | — | 5.15.0-1038.42 |
References
Similar Threats
- Unknown CGA-23jx-hhcx-m389
- Unknown CGA-2qp7-6757-fmgc
- Unknown CGA-2rj5-jc55-r267
- Unknown CGA-3m96-cwq8-6xmx
- Unknown CGA-3qj9-973w-fh9g
Site Security Check
Concerned your site may already be targeted?
BotEraser analyzes incoming traffic patterns and helps identify bot behavior consistent with known exploit attempts.
Check My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.