PT-2022-7231 · Linux+10 · Linux Kernel+10

Lin Ma

·

Published

2022-03-03

·

Updated

2026-03-26

·

CVE-2023-6040

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel versions prior to 5.18-rc1 Linux Kernel versions 5.4.y Linux Kernel versions 5.10.y Linux Kernel versions 5.15.y
Description The issue is related to an out-of-bounds access vulnerability in the nf tables newtable function of the Linux Kernel's netfilter module. This vulnerability can be exploited to gain unauthorized access to protected information. The lack of a safeguard against invalid nf tables family values within the nf tables newtable function enables an attacker to achieve out-of-bounds access. Disabling unprivileged user namespaces can mitigate the issue.
Recommendations For Linux Kernel versions 5.4.y, consider disabling unprivileged user namespaces to minimize the risk of exploitation. For Linux Kernel versions 5.10.y, consider disabling unprivileged user namespaces to minimize the risk of exploitation. For Linux Kernel versions 5.15.y, consider disabling unprivileged user namespaces to minimize the risk of exploitation. For Linux Kernel versions prior to 5.18-rc1, consider disabling unprivileged user namespaces to minimize the risk of exploitation. As a temporary workaround, consider restricting the use of the nf tables newtable function until a patch is available.

Fix

Out of bounds Read

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2024:2394
ALSA-2024:7000
ALSA-2024:7001
ALT-PU-2024-17575
ALT-PU-2024-1838
AZL-33549
BDU:2024-00474
CESA-2024_7000
CESA-2024_7001
CVE-2023-6040
DLA-3840-1
DLA-3841-1
INFSA-2024_2394
INFSA-2024_7000
INFSA-2024_7001
LSN-0100-1
OESA-2024-1097
OPENSUSE-SU-2024_0469-1
OPENSUSE-SU-2024_0515-1
RHSA-2024:2394
RHSA-2024:7000
RHSA-2024:7001
RHSA-2024_2394
RHSA-2024_7000
RHSA-2024_7001
RLSA-2024:7001
SUSE-SU-2024:0463-1
SUSE-SU-2024:0468-1
SUSE-SU-2024:0469-1
SUSE-SU-2024:0474-1
SUSE-SU-2024:0476-1
SUSE-SU-2024:0478-1
SUSE-SU-2024:0483-1
SUSE-SU-2024:0484-1
SUSE-SU-2024:0514-1
SUSE-SU-2024:0515-1
SUSE-SU-2024:0516-1
SUSE-SU-2026:1078-1
USN-6605-1
USN-6605-2
USN-6607-1
USN-6609-1
USN-6609-2
USN-6609-3
USN-6628-1
USN-6628-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linux Kernel
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu