CVE-2023-52924
published 2025-02-05CVE-2023-52924: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetry between…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: don't skip expired elements during walk
There is an asymmetry between commit/abort and preparation phase if the
following conditions are met:
1. set is a verdict map ("1.2.3.4 : jump foo")
2. timeouts are enabled
In this case, following sequence is problematic:
1. element E in set S refers to chain C
2. userspace requests removal of set S
3. kernel does a set walk to decrement chain->use count for all elements
from preparation phase
4. kernel does another set walk to remove elements from the commit phase
(or another walk to do a chain->use increment for all elements from
abort phase)
If E has already expired in 1), it will be ignored during list walk, so its use count
won't have been changed.
Then, when set is culled, ->destroy callback will zap the element via
nf_tables_set_elem_destroy(), but this function is only safe for
elements that have been deactivated earlier from the preparation phase:
lack of earlier deactivate removes the element but leaks the chain use
count, which results in a WARN splat when the chain gets removed later,
plus a leak of the nft_chain structure.
Update pipapo_get() not to skip expired elements, otherwise flush
command reports bogus ENOENT errors.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 94313a196b44184b5b52c1876da6a537701b425a | 94313a196b44184b5b52c1876da6a537701b425a |
| linux | linux | >= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 1da4874d05da1526b11b82fc7f3c7ac38749ddf8 | 1da4874d05da1526b11b82fc7f3c7ac38749ddf8 |
| linux | linux | >= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < b15ea4017af82011dd55225ce77cce3d4dfc169c | b15ea4017af82011dd55225ce77cce3d4dfc169c |
| linux | linux | >= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 7c7e658a36f8b1522bd3586d8137e5f93a25ddc5 | 7c7e658a36f8b1522bd3586d8137e5f93a25ddc5 |
| linux | linux | >= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 59dab3bf0b8fc08eb802721c0532f13dd89209b8 | 59dab3bf0b8fc08eb802721c0532f13dd89209b8 |
| linux | linux | >= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < bd156ce9553dcaf2d6ee2c825d1a5a1718e86524 | bd156ce9553dcaf2d6ee2c825d1a5a1718e86524 |
| linux | linux | >= 9d0982927e79049675cb6c6c04a0ebb3dad5a434 < 24138933b97b055d486e8064b4a1721702442a9b | 24138933b97b055d486e8064b4a1721702442a9b |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 4.1 < 4.19.316 | 4.19.316 |
| linux | linux_kernel | >= 4.20 < 5.4.262 | 5.4.262 |
| linux | linux_kernel | >= 5.11 < 5.15.134 | 5.15.134 |
| linux | linux_kernel | >= 5.16 < 6.1.56 | 6.1.56 |
| linux | linux_kernel | >= 5.5 < 5.10.198 | 5.10.198 |
| linux | linux_kernel | >= 6.2 < 6.4.11 | 6.4.11 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4rw8-6238-r9gq: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: don't skip expired elements during walk
There is an asymme
ghsa_unreviewed·2025-02-05
CVE-2023-52924 [MEDIUM] GHSA-4rw8-6238-r9gq: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: don't skip expired elements during walk
There is an asymme
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: don't skip expired elements during walk
There is an asymmetry between commit/abort and preparation phase if the
following conditions are met:
1. set is a verdict map ("1.2.3.4 : jump foo")
2. timeouts are enabled
In this case, following sequence is problematic:
1. element E in set S refers to chain C
2. userspace requests removal of set S
3. kernel does a set walk to decrement chain->use count for all elements
from preparation phase
4. kernel does another set walk to remove elements from the commit phase
(or another walk to do a chain->use increment for all elements from
abort phase)
If E has already expired in 1), it will be ignored during list walk, so its use count
won't have been changed.
T
OSV
CVE-2023-52924: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetr
osv·2025-02-05·CVSS 5.5
CVE-2023-52924 [MEDIUM] CVE-2023-52924: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetr
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetry between commit/abort and preparation phase if the following conditions are met: 1. set is a verdict map ("1.2.3.4 : jump foo") 2. timeouts are enabled In this case, following sequence is problematic: 1. element E in set S refers to chain C 2. userspace requests removal of set S 3. kernel does a set walk to decrement chain->use count for all elements from preparation phase 4. kernel does another set walk to remove elements from the commit phase (or another walk to do a chain->use increment for all elements from abort phase) If E has already expired in 1), it will be ignored during list walk, so its use count won't have been changed. Then, wh
Red Hat
kernel: netfilter: nf_tables: don't skip expired elements during walk
vendor_redhat·2025-02-05·CVSS 5.5
CVE-2023-52924 [MEDIUM] CWE-664 kernel: netfilter: nf_tables: don't skip expired elements during walk
kernel: netfilter: nf_tables: don't skip expired elements during walk
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: don't skip expired elements during walk
There is an asymmetry between commit/abort and preparation phase if the
following conditions are met:
1. set is a verdict map ("1.2.3.4 : jump foo")
2. timeouts are enabled
In this case, following sequence is problematic:
1. element E in set S refers to chain C
2. userspace requests removal of set S
3. kernel does a set walk to decrement chain->use count for all elements
from preparation phase
4. kernel does another set walk to remove elements from the commit phase
(or another walk to do a chain->use increment for all elements from
abort phase)
If E has already expired in 1), it will be ignor
Debian
CVE-2023-52924: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
vendor_debian·2023·CVSS 5.5
CVE-2023-52924 [MEDIUM] CVE-2023-52924: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't skip expired elements during walk There is an asymmetry between commit/abort and preparation phase if the following conditions are met: 1. set is a verdict map ("1.2.3.4 : jump foo") 2. timeouts are enabled In this case, following sequence is problematic: 1. element E in set S refers to chain C 2. userspace requests removal of set S 3. kernel does a set walk to decrement chain->use count for all elements from preparation phase 4. kernel does another set walk to remove elements from the commit phase (or another walk to do a chain->use increment for all elements from abort phase) If E has already expired in 1), it will be ignored during list walk, so its use count won't have been changed. Then, wh
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1da4874d05da1526b11b82fc7f3c7ac38749ddf8https://git.kernel.org/stable/c/24138933b97b055d486e8064b4a1721702442a9bhttps://git.kernel.org/stable/c/59dab3bf0b8fc08eb802721c0532f13dd89209b8https://git.kernel.org/stable/c/7c7e658a36f8b1522bd3586d8137e5f93a25ddc5https://git.kernel.org/stable/c/94313a196b44184b5b52c1876da6a537701b425ahttps://git.kernel.org/stable/c/b15ea4017af82011dd55225ce77cce3d4dfc169chttps://git.kernel.org/stable/c/bd156ce9553dcaf2d6ee2c825d1a5a1718e86524
2025-02-05
Published