kernel CVE-2023-31436
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.14.2
Patched versions
1.14.2
kernel-5.15
(bottlerocket)
< 1.14.2
1.14.2
An out-of-bounds memory access flaw was found in the Linux kernel’s traffic control (QoS) subsystem in how a user triggers the
qfq_change_class
function with an incorrect MTU value of the network device used as lmax. This flaw could lead to a crash or a potential escalation of privileges on the system.