CVE-2023-5197 — Use After Free in Kernel
Severity
6.6MEDIUMNVD
CNA7.8
EPSS
0.1%
top 81.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 27
Latest updateJan 10
Description
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free.
We recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:HExploitability: 1.8 | Impact: 4.7
Affected Packages3 packages
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-5xr7-jj63-cqf7: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation↗2023-09-27
OSV▶
CVE-2023-5197: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation↗2023-09-27
📋Vendor Advisories
16💬Community
1Bugzilla▶
CVE-2023-5197 kernel: netfilter: nf_tables: use-after-free due to addition and removal of rules from chain bindings within the same transaction↗2023-09-28