CVE-2023-1829: Linux Kernel
High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.
A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root. We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ .
Affected products
- Linux Linux Kernel: before 4.14.308 (fixed in 4.14.308); from 4.15, before 4.19.276 (fixed in 4.19.276); from 4.20, before 5.4.235 (fixed in 5.4.235); from 5.5, before 5.10.173 (fixed in 5.10.173); from 5.11, before 5.15.100 (fixed in 5.15.100); from 5.16, before 6.1.18 (fixed in 6.1.18); …
Published 2023-04-12. Last modified 2026-07-29.