Vulnerabilities in the Linux kernel's QoS subsystem allowing privilege elevation in the system
Two vulnerabilities (CVE-2023-1281, CVE-2023-1829) have been discovered in the Linux kernel, allowing local users to elevate their privileges within the system. To exploit these vulnerabilities, the user needs the ability to create and modify traffic classifiers, which is available with CAP_NET_ADMIN rights that can be obtained by having the capability to create user namespaces. The issues appear starting from kernel 4.14 and have been fixed in the 6.2 branch […]
