CVE-2023-3609

Executive Summary

CVE-2023-3609 exposes a use‑after‑free flaw in the Linux kernel’s net/sched:cls_u32 module. If tcf_change_indev() fails, the reference counter in tcf_bind_filter() can be manipulated to zero, freeing the object prematurely. An attacker with local access can exploit this to gain root privileges. The issue is mitigated by applying the patch commit 04c55383fa5689357bcdd2c8036725a55ed632bc. No current CISA KEV listing.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2023-07-21T21:15:11.743 - Last Modified: 2026-09-11T16:16:30.007

Original Description: A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation.

If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.

We recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc.

"The bird of paradise alights only upon the hand that does not grasp."

— John Berry
Source: NVD