kernel CVE-2023-4128
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.15.0
Patched versions
1.15.0
kernel-5.15
(bottlerocket)
< 1.15.0
1.15.0
A use-after-free flaw was found in net/sched/cls_fw.c in classifiers (cls_fw, cls_u32, and cls_route) in the Linux Kernel. This flaw allows a local user to perform a privilege escalation due to incorrect handling of the existing filter leading to a kernel information leak issue.