CVE-2024-26898
Linux Linux, linux_kernel, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
In the Linux kernel, the following vulnerability has been resolved: aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts This patch is against CVE-2023-6270. The description of cve is: A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential code execution. In aoecmd_cfg_pkts(), it always...
- CVSS
- 7.8
- EPSS
- 0.30% 22.8% percentile
- CISA KEV
- Not listed
- Published
- 2024.04.17