PT-2023-7887 · Linux+9 · Linux Kernel+9

Lonial Kong

+1

·

Published

2023-12-15

·

Updated

2024-08-12

·

CVE-2023-6817

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.7-rc5 Linux kernel versions 5.6 through 5.10.203 Linux kernel versions 5.6 through 5.15.142 Linux kernel versions 5.6 through 6.1.67 Linux kernel versions 5.6 through 6.6.6
Description A use-after-free vulnerability in the Linux kernel's netfilter: nf tables component can be exploited to achieve local privilege escalation. The function nft pipapo walk did not skip inactive elements during set walk, which could lead to double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free. This issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information and elevate their privileges in the system.
Recommendations Upgrade past commit 317eb9685095678f2c9f5a8189de698c5354316a. For Linux kernel versions 5.10, upgrade to version 5.10.204 or later. For Linux kernel versions 5.15, upgrade to version 5.15.143 or later. For Linux kernel versions 6.1, upgrade to version 6.1.68 or later. For Linux kernel versions 6.6, upgrade to version 6.6.7 or later. As a temporary workaround, consider disabling the nft pipapo walk function until a patch is available.

Exploit

Fix

DoS

LPE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:0897
ALT-PU-2023-8275
ALT-PU-2023-8276
ALT-PU-2023-8282
ALT-PU-2023-8337
ALT-PU-2023-8392
ALT-PU-2024-1049
ALT-PU-2024-2275
ALT-PU-2024-4263
ALT-PU-2024-4843
AZL-62609
BDU:2023-08958
CESA-2024_0881
CESA-2024_0897
CVE-2023-6817
DLA-3711-1
DSA-5593-1
DSA-5594-1
LSN-0100-1
LSN-0101-1
LSN-0103-1
OESA-2024-1032
OESA-2024-1033
OESA-2024-1034
OESA-2024-1035
OPENSUSE-SU-2024_0857-1
OPENSUSE-SU-2024_0858-1
RHSA-2024:0724
RHSA-2024:0881
RHSA-2024:0897
RHSA-2024:1018
RHSA-2024:1019
RHSA-2024:1248
RHSA-2024:1268
RHSA-2024:1269
RHSA-2024:1367
RHSA-2024:1382
RHSA-2024:1404
RHSA-2024:3414
RHSA-2024:3421
RHSA-2024_0881
RHSA-2024_0897
RHSA-2024_1248
RXSA-2024:1248
SUSE-SU-2024:0855-1
SUSE-SU-2024:0856-1
SUSE-SU-2024:0857-1
SUSE-SU-2024:0858-1
SUSE-SU-2024:0900-1
SUSE-SU-2024:0900-2
SUSE-SU-2024:0910-1
SUSE-SU-2024:0977-1
USN-6606-1
USN-6607-1
USN-6608-1
USN-6608-2
USN-6609-1
USN-6609-2
USN-6609-3
USN-6628-1
USN-6628-2
USN-6635-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu