CVE-2023-6270 Information
Jan 05, 2024
cve
Description
A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on struct net_device and a use-after-free can be triggered by racing between the free on the struct and the access through the skbtxq global queue. This could lead to a denial of service condition or potential code execution.
Reference
https://access.redhat.com/security/cve/CVE-2023-6270 https://bugzilla.redhat.com/show_bug.cgi?id=2256786
Share on: