CVE-2023-6932 is a use-after-free vulnerability in the Linux kernel's IPv4 IGMP component, affecting Debian and other Linux distributions. It allows for local privilege escalation due to a race condition that incorrectly registers a timer on a freed object. Rated 7.0 HIGH, exploitation requires local access and has high impact on confidentiality, integrity, and availability, though with high attack complexity. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.12, < 6.7CPE match | cpe:2.3:a:linux:kernel:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
< 4.14.332CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.301CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.263CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-6932
Jun 11, 2024kernel: use-after-free in IPv4 IGMP
Dec 19, 2023Use-after-free in Linux kernel's ipv4: igmp component
Dec 12, 2023OVMSA-2024-0006: Unbreakable Enterprise kernel security update (IMPORTANT)