PT-2025-38022 · Linux+2 · Linux Kernel+2
Published
2025-09-16
·
Updated
2025-11-19
·
CVE-2023-53304
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains an issue within the netfilter module, specifically in the
nft set rbtree function, related to interval overlap expiration handling. A flaw in the lazy garbage collection process during insertion can fail to release interval halves, potentially leading to memory leaks. Additionally, an incorrect comparison of pointers (rbe prev vs. prev) can cause incorrect removal of intervals. The issue also involves a missing check of the generation mask for end intervals to ensure they are active in the current generation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse