A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.
Version | Score | Severity | Vector String |
---|---|---|---|
3.1 | 7 | High | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Product | Vendor | Version |
---|---|---|
Red Hat Enterprise Linux 6 | Red Hat | 5.13 |
Red Hat Enterprise Linux 7 | Red Hat | < 10.0.10240.19747 |
Red Hat Enterprise Linux 8 | Red Hat | <= 6.6.* |
Red Hat Enterprise Linux 9 | Red Hat | >=15.8, <15.8.4 |
n/a | ||
Red Hat Enterprise Linux 7 | Red Hat | <= 6.1.* |
Red Hat Enterprise Linux 9 | Red Hat | < publication |
Red Hat Enterprise Linux 8 | Red Hat | <= 6.9.* |