A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unprivileged user to crash the system, causing a denial of service.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 6.0-rc3 | 6.0-rc3.x |
| linux / linux_kernel | 6.0-rc1 | 6.0-rc1.x |
| linux / linux_kernel | 6.0-rc2 | 6.0-rc2.x |
| linux / linux_kernel | 6.0-rc4 | 6.0-rc4.x |
| debian / debian_linux | 10.0 | 10.0.x |
| linux / linux_kernel | 2.6.39 | 5.19.x |