CVE-2023-6270

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution.

Scoring

Severity
HIGH
CVSS base score
7
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS probability
0.02%
CWE
CWE-911, CWE-416
Published
2024-01-04
Last modified
2026-03-24

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs