PT-2025-5682 · Linux+3 · Linux Kernel+3
Published
2023-08-12
·
Updated
2025-07-28
·
CVE-2023-52925
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The issue concerns the Linux kernel's netfilter component, specifically the nf tables subsystem. It has been observed that insertion operations should ignore duplicate but expired entries. Additionally, there is an asymmetry in the
nft pipapo activate function, where it refetches the current element, unlike other ->activate callbacks that use elem->priv. The same issue is present in the .remove function, where nft pipapo remove fetches elem->priv and then performs a relookup, which should be removed. The pipapo get() helper is used for normal get requests, insertions, and deactivate callbacks, and it has been noted that skipping expired elements in this context does not make sense. The nftables selftests have failed, indicating an issue with the current implementation.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse