CVE-2023-32233
high · 7.8In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.
7.8
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2023-05-08
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-416
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| linux | linux_kernel | >= 3.13, < 4.14.315 |
| linux | linux_kernel | >= 4.15, < 4.19.283 |
| linux | linux_kernel | >= 4.20, < 5.4.243 |
| linux | linux_kernel | >= 5.5, < 5.10.180 |
| linux | linux_kernel | >= 5.11, < 5.15.111 |
| linux | linux_kernel | >= 5.16, < 6.1.28 |
| linux | linux_kernel | >= 6.2, < 6.2.15 |
| linux | linux_kernel | >= 6.3, < 6.3.2 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| netapp | hci_baseboard_management_controller | h300s |
| netapp | hci_baseboard_management_controller | h410c |
| netapp | hci_baseboard_management_controller | h410s |
| netapp | hci_baseboard_management_controller | h500s |
| netapp | hci_baseboard_management_controller | h700s |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html
- http://www.openwall.com/lists/oss-security/2023/05/15/5
- https://bugzilla.redhat.com/show_bug.cgi?id=2196105
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c1592a89942e9678f7d9c8030efa777c0d57edab
- https://github.com/torvalds/linux/commit/c1592a89942e9678f7d9c8030efa777c0d57edab
- https://lists.debian.org/debian-lts-announce/2023/06/msg00008.html
- https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html
- https://news.ycombinator.com/item?id=35879660
- https://security.netapp.com/advisory/ntap-20230616-0002/
- https://www.debian.org/security/2023/dsa-5402
- https://www.openwall.com/lists/oss-security/2023/05/08/4
- http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.html
- http://www.openwall.com/lists/oss-security/2023/05/15/5
- https://bugzilla.redhat.com/show_bug.cgi?id=2196105
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c1592a89942e9678f7d9c8030efa777c0d57edab
- https://github.com/torvalds/linux/commit/c1592a89942e9678f7d9c8030efa777c0d57edab
- https://lists.debian.org/debian-lts-announce/2023/06/msg00008.html
- https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html
- https://news.ycombinator.com/item?id=35879660
- https://security.netapp.com/advisory/ntap-20230616-0002/
- https://www.debian.org/security/2023/dsa-5402
- https://www.openwall.com/lists/oss-security/2023/05/08/4
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-32233