PT-2024-14667 · Linux+4 · Linux Kernel+4

Published

2023-09-06

·

Updated

2025-09-29

·

CVE-2023-52628

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel versions prior to 4.1 cycle and all versions after 4.1 cycle before the fix
Description The issue is related to a stack-based buffer overflow in the netfilter component of the Linux kernel. If priv->len is a multiple of 4, then dst[len / 4] can write past the destination array, leading to stack corruption. This occurs because a construct is necessary to clean the remainder of the register in case ->len is not a multiple of the register size. The bug was added in the 4.1 cycle and then copied or inherited when tcp/sctp and ip option support was added.
Recommendations As a temporary workaround, consider disabling the nft exthdr function until a patch is available. Restrict access to the vulnerable netfilter module to minimize the risk of exploitation. Avoid using the priv->len variable in the affected code until the issue is resolved. Update to a version of the Linux Kernel that includes the fix for the netfilter: nftables: exthdr: fix 4-byte stack OOB write issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-15304
CVE-2023-52628
DLA-3840-1
OESA-2024-1617
OESA-2024-1619
OESA-2024-1620
OESA-2024-1621
OESA-2024-1622
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1489-1
OPENSUSE-SU-2024_1490-1
OPENSUSE-SU-2024_1641-1
RHSA-2024:2394
RHSA-2024:2845
RHSA-2024:2846
RHSA-2024:3414
RHSA-2024:3421
RHSA-2024_2394
SUSE-SU-2024:1454-1
SUSE-SU-2024:1465-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1489-1
SUSE-SU-2024:1490-1
SUSE-SU-2024:1641-1
SUSE-SU-2024:1643-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1647-1
SUSE-SU-2024:1870-1
SUSE-SU-2024:2091-1
SUSE-SU-2024:2094-1
SUSE-SU-2024:2109-1
SUSE-SU-2024:2124-1
SUSE-SU-2024:2156-1
SUSE-SU-2024:2164-1
SUSE-SU-2024:2216-1
SUSE-SU-2024:2217-1
ZDI-24-297
ZDI-24-298
ZDI-24-299

Affected Products

Astra Linux
Linux Kernel
Red Hat
Red Os
Suse