← All CVEs

CVE-2023-32233

high · 7.8

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

7.8
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2023-05-08
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 3.13, < 4.14.315
linuxlinux_kernel>= 4.15, < 4.19.283
linuxlinux_kernel>= 4.20, < 5.4.243
linuxlinux_kernel>= 5.5, < 5.10.180
linuxlinux_kernel>= 5.11, < 5.15.111
linuxlinux_kernel>= 5.16, < 6.1.28
linuxlinux_kernel>= 6.2, < 6.2.15
linuxlinux_kernel>= 6.3, < 6.3.2
redhatenterprise_linux7.0
redhatenterprise_linux8.0
redhatenterprise_linux9.0
netapphci_baseboard_management_controllerh300s
netapphci_baseboard_management_controllerh410c
netapphci_baseboard_management_controllerh410s
netapphci_baseboard_management_controllerh500s
netapphci_baseboard_management_controllerh700s

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-32233