PT-2025-5682 · Linux+3 · Linux Kernel+3

Published

2023-08-12

·

Updated

2025-07-28

·

CVE-2023-52925

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue concerns the Linux kernel's netfilter component, specifically the nf tables subsystem. It has been observed that insertion operations should ignore duplicate but expired entries. Additionally, there is an asymmetry in the nft pipapo activate function, where it refetches the current element, unlike other ->activate callbacks that use elem->priv. The same issue is present in the .remove function, where nft pipapo remove fetches elem->priv and then performs a relookup, which should be removed. The pipapo get() helper is used for normal get requests, insertions, and deactivate callbacks, and it has been noted that skipping expired elements in this context does not make sense. The nftables selftests have failed, indicating an issue with the current implementation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06376
CVE-2023-52925
OPENSUSE-SU-2025_0847-1
OPENSUSE-SU-2025_0856-1
OPENSUSE-SU-2025_0955-1
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:0784-1
SUSE-SU-2025:0847-1
SUSE-SU-2025:0856-1
SUSE-SU-2025:0955-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1
SUSE-SU-2025_0847-1
SUSE-SU-2025_0856-1
SUSE-SU-2025_0955-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse