A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on struct net_device, and a use-after-free can be triggered by racing between the free on the struct and the access through the skbtxq global queue. This could lead to a denial of service condition or potential code execution.
| Software | From | Fixed in |
|---|---|---|
| fedoraproject / fedora | 39 | 39.x |
| debian / debian_linux | 10.0 | 10.0.x |
| linux / linux_kernel | - | 6.9 |