CVE-2023-4623

Updated: 2025-08-20 02:53:17.770087

Description:

A use-after-free vulnerability in the Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component can be exploited to achieve local privilege escalation. If a class with a link-sharing curve (i.e. with the HFSC_FSC flag set) has a parent without a link-sharing curve, then init_vf() will call vttree_insert() on the parent, but vttree_remove() will be skipped in update_vf(). This leaves a dangling pointer that can cause a use-after-free. We recommend upgrading past commit b3d26c5702c7d6c45456326e56d2ccf3f103e60f.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released CLSA-2024:1712570434 2024-04-08 10:43:30
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2024:1705494430 2024-02-05 08:28:45
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2024:1720468480 2024-07-23 17:28:56
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2023:1701963303 2023-12-07 13:11:47
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2023:1701962635 2023-12-07 13:11:48
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Ignored 2024-10-09 04:10:37
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2024:1705496067 2024-01-17 08:41:14
RHEL 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2025:1750353839 2025-06-20 00:27:53
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Released CLSA-2023:1698305104 2023-10-26 07:38:41
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2023:1698247974 2023-10-25 14:06:45
Total: 11