PT-2023-4957 · Linux+10 · Linux Kernel+10
Bien Pham
·
Publicado
2023-08-10
·
Atualizado
2026-06-18
·
CVE-2023-4244
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to the commit 3e91b0ebd994635df2346353322ac51ce84ce6d8
Description
A use-after-free vulnerability in the Linux kernel's netfilter: nf tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf tables netlink control plane transaction and nft set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability.
Recommendations
Upgrade past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8 to resolve the issue. As a temporary workaround, consider restricting access to the nf tables component to minimize the risk of exploitation.
Exploit
Correção
DoS
LPE
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu