CVE-2023-4015Use After Free in Kernel

CWE-416Use After Free19 documents10 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 90.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 6
Latest updateOct 6

Description

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. On an error when building a nftables rule, deactivating immediate expressions in nft_immediate_deactivate() can lead unbinding the chain and objects be deactivated but later used. We recommend upgrading past commit 0a771f7b266b02d262900c75f1e175c7fe76fec2.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5linux/kernel6.46.5
NVDlinux/linux_kernel5.95.10.190+3
Debianlinux/linux_kernel< 6.1.52-1+2

Also affects: Debian Linux 12.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5m5v-w78j-286f: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation2023-09-06
OSV
CVE-2023-4015: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation2023-09-06
CVEList
Use-after-free in Linux kernel's netfilter: nf_tables component2023-09-06

📋Vendor Advisories

14
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-40152023-10-06
Ubuntu
Linux kernel (OEM) vulnerabilities2023-09-19
Microsoft
Use-after-free in Linux kernel's netfilter: nf_tables component2023-09-12
Red Hat
kernel: use after free in nft_immediate_deactivate2023-09-06
Ubuntu
Linux kernel vulnerabilities2023-09-06

💬Community

1
Bugzilla
CVE-2023-4015 kernel: use after free in nft_immediate_deactivate2023-09-06
CVE-2023-4015 — Use After Free in Linux Kernel | cvebase