CVE-2023-6270: Debian Linux
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 39 only
- Linux Linux Kernel: before 6.9 (fixed in 6.9)
Published 2024-01-04. Last modified 2026-06-17.