cbcvebase.
CVE-2023-32233
published 2023-05-08

CVE-2023-32233: In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.27-1 (bookworm)linux 6.1.27-1 (bookworm)
googlechrome_chrome
linuxlinux_kernel>= 0 < 5.10.179-15.10.179-1
linuxlinux_kernel>= 0 < 6.1.27-16.1.27-1
linuxlinux_kernel>= 0 < 6.1.27-16.1.27-1
linuxlinux_kernel>= 0 < 6.1.27-16.1.27-1
linuxlinux_kernel>= 0 < 4.15.0-212.2234.15.0-212.223
linuxlinux_kernel>= 0 < 5.4.0-150.1675.4.0-150.167
linuxlinux_kernel>= 0 < 5.15.0-73.805.15.0-73.80
linuxlinux_kernel>= 0 < 4.4.0-241.2754.4.0-241.275
linuxlinux_kernel>= 0 < 5.4.0-150.1675.4.0-150.167
linuxlinux_kernel>= 0 < 5.15.0-73.805.15.0-73.80
linuxlinux_kernel>= 3.13 < 4.14.3154.14.315
linuxlinux_kernel>= 4.15 < 4.19.2834.19.283
linuxlinux_kernel>= 4.20 < 5.4.2435.4.243
linuxlinux_kernel>= 5.11 < 5.15.1115.15.111
linuxlinux_kernel>= 5.16 < 6.1.286.1.28
linuxlinux_kernel>= 5.5 < 5.10.1805.10.180
linuxlinux_kernel>= 6.2 < 6.2.156.2.15
linuxlinux_kernel>= 6.3 < 6.3.26.3.2
msrccbl2_kernel_5.15.112.1-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vulncheck7.8HIGH