PT-2023-3470 · Linux+2 · Linux Kernel+2

Published

2023-06-07

·

Updated

2023-09-04

·

CVE-2023-3117

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a use-after-free flaw in the Netfilter subsystem of the Linux kernel when processing named and anonymous sets in batch requests. This can lead to performing arbitrary reads and writes in kernel memory. A local user with CAP NET ADMIN capability can potentially crash the system or escalate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4368
ALT-PU-2023-4401
ALT-PU-2023-4482
ALT-PU-2023-4663
BDU:2023-03656
CVE-2023-3117
OESA-2023-1435
OESA-2023-1436
OESA-2023-1437
OESA-2023-1438
OESA-2023-1439
OPENSUSE-SU-2023_3171-1
OPENSUSE-SU-2023_3172-1
OPENSUSE-SU-2023_3180-1
OPENSUSE-SU-2023_3182-1
OPENSUSE-SU-2023_3302-1
OPENSUSE-SU-2023_3318-1
OPENSUSE-SU-2023_3391-1
SUSE-SU-2023:3171-1
SUSE-SU-2023:3172-1
SUSE-SU-2023:3180-1
SUSE-SU-2023:3182-1
SUSE-SU-2023:3302-1
SUSE-SU-2023:3318-1
SUSE-SU-2023:3390-1
SUSE-SU-2023:3391-1
SUSE-SU-2023:3421-1
SUSE-SU-2023_3171-1
SUSE-SU-2023_3172-1
SUSE-SU-2023_3180-1
SUSE-SU-2023_3182-1

Affected Products

Linux Kernel
Red Os
Suse