A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2024-01-04T17:01:51.165Z

Updated: 2024-04-25T15:55:52.424Z

Reserved: 2023-11-23T14:31:28.637Z


Link: CVE-2023-6270

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2024-01-04T17:15:08.803

Modified: 2024-06-27T13:15:54.233


Link: CVE-2023-6270

JSON object: View

cve-icon Redhat Information

No data.

CWE