CVE-2023-6270
Linux Kernel vulnerability analysis and mitigation

Overview

A flaw was discovered in the ATA over Ethernet (AoE) driver in the Linux kernel, identified as CVE-2023-6270. The vulnerability was disclosed on January 4, 2024, affecting Linux kernel systems with the AoE driver enabled. The issue stems from improper reference counting in the aoecmd_cfg_pkts() function when handling network device structures (Ubuntu Security, NVD).

Technical details

The vulnerability occurs in the aoecmd_cfg_pkts() function of the AoE driver, which improperly updates the reference count (refcnt) on struct net_device. This implementation flaw can lead to a use-after-free condition when there is a race between freeing the struct and accessing it through the skbtxq global queue. The vulnerability has been assigned a CVSS 3 Severity Score of 7.0 (High) (Ubuntu Security).

Impact

The exploitation of this vulnerability could lead to a denial of service condition or potentially allow arbitrary code execution. The high severity rating indicates significant potential impact on system security, particularly concerning for systems utilizing the ATA over Ethernet driver (Ubuntu Security, Rapid7).

Mitigation and workarounds

The vulnerability has been fixed in multiple Linux kernel versions across different distributions. Ubuntu has released patches for various kernel versions including 6.8.0-35.35 for 24.04 LTS, 6.5.0-44.44 for 23.10, and 5.15.0-112.122 for 22.04 LTS. Debian has also addressed this in version 5.10.216-1~deb10u1. Users are advised to update their kernel to the latest patched version (Ubuntu Security, Debian Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-cross-headers
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-modules-core
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management