kernel CVE-2023-3609
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.15.0
Patched versions
1.15.0
kernel-5.15
(bottlerocket)
< 1.15.0
1.15.0
A double-free flaw was found in u32_set_parms in net/sched/cls_u32.c in the Network Scheduler component in the Linux kernel. This flaw allows a local user to use a failure event to mishandle the reference counter, leading to a possible local privilege escalation.