跳转到帖子

Amazon Linux AMI 2: CVE-2023-4208: Security patch for kernel, kernel-livepatch-4.14.320-243.544, kernel-livepatch-5.10.186-179.751 (Multiple Advisories)

recommended_posts

发布于
  • Members

Amazon Linux AMI 2: CVE-2023-4208: Security patch for kernel, kernel-livepatch-4.14.320-243.544, kernel-livepatch-5.10.186-179.751 (Multiple Advisories)

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
09/06/2023
Created
10/04/2023
Added
10/04/2023
Modified
01/30/2025

Description

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. When u32_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free. We recommend upgrading past commit 3044b16e7c6fe5d24b1cdbcf1bd0a9d92d1ebd81.

Solution(s)

  • amazon-linux-ami-2-upgrade-bpftool
  • amazon-linux-ami-2-upgrade-bpftool-debuginfo
  • amazon-linux-ami-2-upgrade-kernel
  • amazon-linux-ami-2-upgrade-kernel-debuginfo
  • amazon-linux-ami-2-upgrade-kernel-debuginfo-common-aarch64
  • amazon-linux-ami-2-upgrade-kernel-debuginfo-common-x86_64
  • amazon-linux-ami-2-upgrade-kernel-devel
  • amazon-linux-ami-2-upgrade-kernel-headers
  • amazon-linux-ami-2-upgrade-kernel-livepatch-4-14-320-243-544
  • amazon-linux-ami-2-upgrade-kernel-livepatch-4-14-320-243-544-debuginfo
  • amazon-linux-ami-2-upgrade-kernel-livepatch-4-14-322-244-536
  • amazon-linux-ami-2-upgrade-kernel-livepatch-5-10-186-179-751
  • amazon-linux-ami-2-upgrade-kernel-livepatch-5-10-186-179-751-debuginfo
  • amazon-linux-ami-2-upgrade-kernel-livepatch-5-10-192-182-736
  • amazon-linux-ami-2-upgrade-kernel-livepatch-5-15-128-80-144
  • amazon-linux-ami-2-upgrade-kernel-tools
  • amazon-linux-ami-2-upgrade-kernel-tools-debuginfo
  • amazon-linux-ami-2-upgrade-kernel-tools-devel
  • amazon-linux-ami-2-upgrade-perf
  • amazon-linux-ami-2-upgrade-perf-debuginfo
  • amazon-linux-ami-2-upgrade-python-perf
  • amazon-linux-ami-2-upgrade-python-perf-debuginfo

References

  • https://attackerkb.com/topics/cve-2023-4208
  • AL2/ALAS-2023-2268
  • AL2/ALASKERNEL-5.10-2023-039
  • AL2/ALASKERNEL-5.15-2023-026
  • AL2/ALASKERNEL-5.4-2023-054
  • AL2/ALASLIVEPATCH-2023-154
  • AL2/ALASLIVEPATCH-2023-155
  • CVE - 2023-4208
View more
  • 查看数 704
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…