cbcvebase.
CVE-2023-52924
published 2025-02-05

CVE-2023-52924: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetry between…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.0th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetry between commit/abort and preparation phase if the following conditions are met: 1. set is a verdict map ("1.2.3.4 : jump foo") 2. timeouts are enabled In this case, following sequence is problematic: 1. element E in set S refers to chain C 2. userspace requests removal of set S 3. kernel does a set walk to decrement chain->use count for all elements from preparation phase 4. kernel does another set walk to remove elements from the commit phase (or another walk to do a chain->use increment for all elements from abort phase) If E has already expired in 1), it will be ignored during list walk, so its use count won't have been changed. Then, when set is culled, ->destroy callback will zap the element via nf_tables_set_elem_destroy(), but this function is only safe for elements that have been deactivated earlier from the preparation phase: lack of earlier deactivate removes the element but leaks the chain use count, which results in a WARN splat when the chain gets removed later, plus a leak of the nft_chain structure. Update pipapo_get() not to skip expired elements, otherwise flush command reports bogus ENOENT errors.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 94313a196b44184b5b52c1876da6a537701b425a94313a196b44184b5b52c1876da6a537701b425a
linuxlinux>= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 1da4874d05da1526b11b82fc7f3c7ac38749ddf81da4874d05da1526b11b82fc7f3c7ac38749ddf8
linuxlinux>= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < b15ea4017af82011dd55225ce77cce3d4dfc169cb15ea4017af82011dd55225ce77cce3d4dfc169c
linuxlinux>= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 7c7e658a36f8b1522bd3586d8137e5f93a25ddc57c7e658a36f8b1522bd3586d8137e5f93a25ddc5
linuxlinux>= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 59dab3bf0b8fc08eb802721c0532f13dd89209b859dab3bf0b8fc08eb802721c0532f13dd89209b8
linuxlinux>= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < bd156ce9553dcaf2d6ee2c825d1a5a1718e86524bd156ce9553dcaf2d6ee2c825d1a5a1718e86524
linuxlinux>= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 24138933b97b055d486e8064b4a1721702442a9b24138933b97b055d486e8064b4a1721702442a9b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 4.1 < 4.19.3164.19.316
linuxlinux_kernel>= 4.20 < 5.4.2625.4.262
linuxlinux_kernel>= 5.11 < 5.15.1345.15.134
linuxlinux_kernel>= 5.16 < 6.1.566.1.56
linuxlinux_kernel>= 5.5 < 5.10.1985.10.198
linuxlinux_kernel>= 6.2 < 6.4.116.4.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.