Vulnerabilities in the Linux kernel's QoS subsystem allowing privilege elevation in the system

Two vulnerabilities (CVE-2023-1281, CVE-2023-1829) have been identified in the Linux kernel, allowing a local user to escalate their privileges in the system. To exploit these vulnerabilities, permission to create and modify traffic classifiers is required, which is available with CAP_NET_ADMIN rights that can be obtained if user namespace creation is possible. The issues manifest starting from kernel version 4.14 and have been fixed in branch 6.2.

The vulnerabilities are caused by a use-after-free condition in the tcindex traffic classifier code, part of the Linux kernel's QoS (Quality of Service) subsystem. The first vulnerability arises from a race condition when updating suboptimal hash filters, while the second vulnerability occurs during the deletion of an optimal hash filter. You can track the fixes in distributions on the following pages: Debian, Ubuntu, Gentoo, RHEL, SUSE, Fedora, Gentoo, Arch. To block the exploitation of the vulnerability, you can disable the ability to create namespaces by unprivileged users with the command ('sudo sysctl -w kernel.unprivileged_userns_clone=0').

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster