CVE-2023-6932: Debian Linux
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread. We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.
Affected products
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: before 4.14.332 (fixed in 4.14.332); from 4.15, before 4.19.301 (fixed in 4.19.301); from 4.20, before 5.4.263 (fixed in 5.4.263); from 5.5, before 5.10.203 (fixed in 5.10.203); from 5.11, before 5.15.142 (fixed in 5.15.142); from 5.16, before 6.1.66 (fixed in 6.1.66); …
Published 2023-12-19. Last modified 2026-06-17.