CVE-2023-4244

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
06/09/2023
Last modified:
13/02/2025

Description

A use-after-free vulnerability in the Linux kernel&amp;#39;s netfilter: nf_tables component can be exploited to achieve local privilege escalation.<br /> <br /> Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability.<br /> <br /> We recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.5 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*