cbcvebase.
CVE-2023-4147
published 2023-08-07

CVE-2023-4147: A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
fedoraprojectfedora
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 5.11 < 5.15.1245.15.124
linuxlinux_kernel>= 5.16 < 6.1.436.1.43
linuxlinux_kernel>= 5.9 < 5.10.1905.10.190
linuxlinux_kernel>= 6.2 < 6.4.86.4.8
msrccbl2_kernel_5.15.126.1-1_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_for_real_time
redhatenterprise_linux_for_real_time_for_nfv
redhatenterprise_linux_server_aus

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH