kernel CVE-2023-3776
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.15.0
Patched versions
1.15.0
kernel-5.15
(bottlerocket)
< 1.15.0
1.15.0
A use-after-free vulnerability was found in fw_set_parms in net/sched/cls_fw.c in network scheduler sub-component in the Linux Kernel. This issue occurs due to a missing sanity check during cleanup at the time of failure, leading to a misleading reference. This may allow a local user to escalate their privileges.