CVE-2023-52581
published 2024-03-02CVE-2023-52581: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak when more than 255 elements expired When more than 255…
PriorityP426medium6.3CVSS 3.1
AVLACHPRLUINSUCHINAH
EPSS
0.26%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix memleak when more than 255 elements expired
When more than 255 elements expired we're supposed to switch to a new gc
container structure.
This never happens: u8 type will wrap before reaching the boundary
and nft_trans_gc_space() always returns true.
This means we recycle the initial gc container structure and
lose track of the elements that came before.
While at it, don't deref 'gc' after we've passed it to call_rcu.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.5.6-1 (forky) | linux 6.5.6-1 (forky) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 448be0774882f95a74fa5eb7519761152add601b < 09c85f2d21ab6b5acba31a037985b13e8e6565b8 | 09c85f2d21ab6b5acba31a037985b13e8e6565b8 |
| linux | linux | >= 5f68718b34a531a556f2f50300ead2862278da26 < 4aea243b6853d06c1d160a9955b759189aa02b14 | 4aea243b6853d06c1d160a9955b759189aa02b14 |
| linux | linux | >= 5f68718b34a531a556f2f50300ead2862278da26 < cf5000a7787cbc10341091d37245a42c119d26c5 | cf5000a7787cbc10341091d37245a42c119d26c5 |
| linux | linux | >= 6.4.11 < 6.5 | 6.5 |
| linux | linux | >= 8da1b048f9a501d3d7d38c188ba09d7d0d5b8c27 < 7cf055b43756b10aa2b851c927c940f5ed652125 | 7cf055b43756b10aa2b851c927c940f5ed652125 |
| linux | linux | >= bbdb3b65aa91aa0a32b212f27780b28987f2d94f < a995a68e8a3b48533e47c856865d109a1f1a9d01 | a995a68e8a3b48533e47c856865d109a1f1a9d01 |
| linux | linux | >= d19e8bf3ea4114dd21fc35da21f398203d7f7df1 < ef99506eaf1dc31feff1adfcfd68bc5535a22171 | ef99506eaf1dc31feff1adfcfd68bc5535a22171 |
| linux | linux | >= ea3eb9f2192e4fc33b795673e56c97a21987f868 < 7e5d732e6902eb6a37b35480796838a145ae5f07 | 7e5d732e6902eb6a37b35480796838a145ae5f07 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 6.5 < 6.5.6 | 6.5.6 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
osv6.3MEDIUM
vendor_redhat7.8HIGH
vendor_debian6.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC OS
cisa_ics·2025-08-14
Siemens SINEC OS
ICS Advisory
##
Siemens SINEC OS
Release DateAugust 14, 2025
Alert CodeICSA-25-226-15
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3.1 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM, SCALANCE
- Vulnerabilities: NULL Pointer Dereference, Use After Free, Unchecked Input for Loop Condition, Out-of-bounds Write, Ou
Red Hat
kernel: netfilter: nf_tables: memory leak when more than 255 elements expired
vendor_redhat·2024-03-02·CVSS 7.8
CVE-2023-52581 [HIGH] CWE-401 kernel: netfilter: nf_tables: memory leak when more than 255 elements expired
kernel: netfilter: nf_tables: memory leak when more than 255 elements expired
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix memleak when more than 255 elements expired
When more than 255 elements expired we're supposed to switch to a new gc
container structure.
This never happens: u8 type will wrap before reaching the boundary
and nft_trans_gc_space() always returns true.
This means we recycle the initial gc container structure and
lose track of the elements that came before.
While at it, don't deref 'gc' after we've passed it to call_rcu.
A use-after-free flaw was found in the Linux kernel’s nftables sub-component due to a race problem between the set GC and transaction in the Linux Kernel. This flaw allows a local attacker to crash the sy
Debian
CVE-2023-52581: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
vendor_debian·2023·CVSS 6.3
CVE-2023-52581 [MEDIUM] CVE-2023-52581: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak when more than 255 elements expired When more than 255 elements expired we're supposed to switch to a new gc container structure. This never happens: u8 type will wrap before reaching the boundary and nft_trans_gc_space() always returns true. This means we recycle the initial gc container structure and lose track of the elements that came before. While at it, don't deref 'gc' after we've passed it to call_rcu.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.5.6-1)
sid: resolved (fixed in 6.5.6-1)
trixie: resolved (fixed in 6.5.6-1)
GHSA
GHSA-mfw5-pp35-j4h8: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix memleak when more than 255 elements expired
When more
ghsa_unreviewed·2024-03-03
CVE-2023-52581 [MEDIUM] CWE-401 GHSA-mfw5-pp35-j4h8: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix memleak when more than 255 elements expired
When more
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix memleak when more than 255 elements expired
When more than 255 elements expired we're supposed to switch to a new gc
container structure.
This never happens: u8 type will wrap before reaching the boundary
and nft_trans_gc_space() always returns true.
This means we recycle the initial gc container structure and
lose track of the elements that came before.
While at it, don't deref 'gc' after we've passed it to call_rcu.
OSV
CVE-2023-52581: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak when more than 255 elements expired When more th
osv·2024-03-02·CVSS 6.3
CVE-2023-52581 [MEDIUM] CVE-2023-52581: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak when more than 255 elements expired When more th
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak when more than 255 elements expired When more than 255 elements expired we're supposed to switch to a new gc container structure. This never happens: u8 type will wrap before reaching the boundary and nft_trans_gc_space() always returns true. This means we recycle the initial gc container structure and lose track of the elements that came before. While at it, don't deref 'gc' after we've passed it to call_rcu.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/09c85f2d21ab6b5acba31a037985b13e8e6565b8https://git.kernel.org/stable/c/4aea243b6853d06c1d160a9955b759189aa02b14https://git.kernel.org/stable/c/7cf055b43756b10aa2b851c927c940f5ed652125https://git.kernel.org/stable/c/7e5d732e6902eb6a37b35480796838a145ae5f07https://git.kernel.org/stable/c/a995a68e8a3b48533e47c856865d109a1f1a9d01https://git.kernel.org/stable/c/cf5000a7787cbc10341091d37245a42c119d26c5https://git.kernel.org/stable/c/ef99506eaf1dc31feff1adfcfd68bc5535a22171https://git.kernel.org/stable/c/09c85f2d21ab6b5acba31a037985b13e8e6565b8https://git.kernel.org/stable/c/4aea243b6853d06c1d160a9955b759189aa02b14https://git.kernel.org/stable/c/7cf055b43756b10aa2b851c927c940f5ed652125https://git.kernel.org/stable/c/7e5d732e6902eb6a37b35480796838a145ae5f07https://git.kernel.org/stable/c/a995a68e8a3b48533e47c856865d109a1f1a9d01https://git.kernel.org/stable/c/cf5000a7787cbc10341091d37245a42c119d26c5https://git.kernel.org/stable/c/ef99506eaf1dc31feff1adfcfd68bc5535a22171
2024-03-02
Published