cbcvebase.
CVE-2023-52927
published 2025-03-14

CVE-2023-52927: In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.7th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table. However, in some scenario, we expect the exp not to be removed when the created ct will not be confirmed, like in OVS and TC conntrack in the following patches. This patch allows exp not to be removed by setting IPS_CONFIRMED in the status of the tmpl.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 1bc91a5ddf3eaea0e0ea957cccf3abdcfcace00e < 3fa58a6fbd1e9e5682d09cdafb08fba004cb12ec3fa58a6fbd1e9e5682d09cdafb08fba004cb12ec
linuxlinux>= 1bc91a5ddf3eaea0e0ea957cccf3abdcfcace00e < 4914109a8e1e494c6aa9852f9e84ec77a5fc643f4914109a8e1e494c6aa9852f9e84ec77a5fc643f
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 5.4.0-215.2355.4.0-215.235
linuxlinux_kernel>= 0 < 5.15.0-139.1495.15.0-139.149
linuxlinux_kernel>= 0 < 4.15.0-237.2494.15.0-237.249
linuxlinux_kernel>= 5.18 < 6.1.1306.1.130
linuxlinux_kernel>= 6.2 < 6.66.6
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.