CVE-2023-1829 is a use-after-free vulnerability in the Linux Kernel's traffic control index filter (tcindex) that allows for local privilege escalation. Specifically, the tcindex_delete function can improperly deactivate filters, leading to a double-free condition. This flaw enables a local attacker to elevate their privileges to root on affected Linux systems. The vulnerability has a CVSS score of 7.8 (High), indicating a significant risk due to its low attack complexity and potential for high impact on confidentiality, integrity, and availability. An attacker requires local access and no user interaction is needed for exploitation. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not yet garnered widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.14.308CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.276CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.235CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.173CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.100CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel privilege escalation (CVE-2023-1281, CVE-2023-1829)
Jun 6, 2023CVE-2023-1829
May 9, 2023kernel: Use-after-free vulnerability in the Linux Kernel traffic control index filter
Apr 20, 2023Use-after-free in tcindex (traffic control index filter) in the Linux Kernel
Apr 11, 2023