CVE-2023-53304
published 2025-09-16CVE-2023-53304: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix overlap expiration walk The lazy gc on insert that should…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_rbtree: fix overlap expiration walk
The lazy gc on insert that should remove timed-out entries fails to release
the other half of the interval, if any.
Can be reproduced with tests/shell/testcases/sets/0044interval_overlap_0
in nftables.git and kmemleak enabled kernel.
Second bug is the use of rbe_prev vs. prev pointer.
If rbe_prev() returns NULL after at least one iteration, rbe_prev points
to element that is not an end interval, hence it should not be removed.
Lastly, check the genmask of the end interval if this is active in the
current generation.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 181859bdfb9734aca449512fccaee4cacce64aed < acaee227cf79c45a5d2d49c3e9a66333a462802c | acaee227cf79c45a5d2d49c3e9a66333a462802c |
| linux | linux | >= 2bf1435fa19d2c58054391b3bba40d5510a5758c < 50cbb9d195c197af671869c8cadce3bd483735a0 | 50cbb9d195c197af671869c8cadce3bd483735a0 |
| linux | linux | >= 318cb24a4c3fce8140afaf84e4d45fcb76fb280b < 89a4d1a89751a0fbd520e64091873e19cc0979e8 | 89a4d1a89751a0fbd520e64091873e19cc0979e8 |
| linux | linux | >= 4aacf3d78424293e318c616016865380b37b9cc5 < 893cb3c3513cf661a0ff45fe0cfa83fe27131f76 | 893cb3c3513cf661a0ff45fe0cfa83fe27131f76 |
| linux | linux | >= 5.10.166 < 5.10.190 | 5.10.190 |
| linux | linux | >= 5.15.91 < 5.15.124 | 5.15.124 |
| linux | linux | >= 6.1.9 < 6.1.43 | 6.1.43 |
| linux | linux | >= 7ab87a326f20c52ff4d9972052d085be951c704b < 8284a79136c384059e85e278da2210b809730287 | 8284a79136c384059e85e278da2210b809730287 |
| linux | linux | >= c9e6978e2725a7d4b6cd23b2facd3f11422c0643 < cd66733932399475fe933cb3ec03e687ed401462 | cd66733932399475fe933cb3ec03e687ed401462 |
| linux | linux | >= c9e6978e2725a7d4b6cd23b2facd3f11422c0643 < f718863aca469a109895cb855e6b81fff4827d71 | f718863aca469a109895cb855e6b81fff4827d71 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 5.10.166 < 5.10.190 | 5.10.190 |
| linux | linux_kernel | >= 5.15.91 < 5.15.124 | 5.15.124 |
| linux | linux_kernel | >= 6.1.9 < 6.1.43 | 6.1.43 |
| linux | linux_kernel | >= 6.2.1 < 6.4.8 | 6.4.8 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53304: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix overlap expiration walk The lazy gc on insert that
osv·2025-09-16·CVSS 5.5
CVE-2023-53304 [MEDIUM] CVE-2023-53304: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix overlap expiration walk The lazy gc on insert that
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix overlap expiration walk The lazy gc on insert that should remove timed-out entries fails to release the other half of the interval, if any. Can be reproduced with tests/shell/testcases/sets/0044interval_overlap_0 in nftables.git and kmemleak enabled kernel. Second bug is the use of rbe_prev vs. prev pointer. If rbe_prev() returns NULL after at least one iteration, rbe_prev points to element that is not an end interval, hence it should not be removed. Lastly, check the genmask of the end interval if this is active in the current generation.
GHSA
GHSA-phm5-wwmp-pqvr: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_rbtree: fix overlap expiration walk
The lazy gc on insert tha
ghsa_unreviewed·2025-09-16
CVE-2023-53304 [MEDIUM] CWE-476 GHSA-phm5-wwmp-pqvr: In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_rbtree: fix overlap expiration walk
The lazy gc on insert tha
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_rbtree: fix overlap expiration walk
The lazy gc on insert that should remove timed-out entries fails to release
the other half of the interval, if any.
Can be reproduced with tests/shell/testcases/sets/0044interval_overlap_0
in nftables.git and kmemleak enabled kernel.
Second bug is the use of rbe_prev vs. prev pointer.
If rbe_prev() returns NULL after at least one iteration, rbe_prev points
to element that is not an end interval, hence it should not be removed.
Lastly, check the genmask of the end interval if this is active in the
current generation.
Red Hat
kernel: Linux kernel: Denial of Service in netfilter due to improper garbage collection
vendor_redhat·2025-09-16·CVSS 5.5
CVE-2023-53304 [MEDIUM] CWE-772 kernel: Linux kernel: Denial of Service in netfilter due to improper garbage collection
kernel: Linux kernel: Denial of Service in netfilter due to improper garbage collection
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_rbtree: fix overlap expiration walk
The lazy gc on insert that should remove timed-out entries fails to release
the other half of the interval, if any.
Can be reproduced with tests/shell/testcases/sets/0044interval_overlap_0
in nftables.git and kmemleak enabled kernel.
Second bug is the use of rbe_prev vs. prev pointer.
If rbe_prev() returns NULL after at least one iteration, rbe_prev points
to element that is not an end interval, hence it should not be removed.
Lastly, check the genmask of the end interval if this is active in the
current generation.
A flaw was found in the Linux kernel's netfilter component, speci
Debian
CVE-2023-53304: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
vendor_debian·2023·CVSS 5.5
CVE-2023-53304 [MEDIUM] CVE-2023-53304: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix overlap expiration walk The lazy gc on insert that should remove timed-out entries fails to release the other half of the interval, if any. Can be reproduced with tests/shell/testcases/sets/0044interval_overlap_0 in nftables.git and kmemleak enabled kernel. Second bug is the use of rbe_prev vs. prev pointer. If rbe_prev() returns NULL after at least one iteration, rbe_prev points to element that is not an end interval, hence it should not be removed. Lastly, check the genmask of the end interval if this is active in the current generation.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.4.11-1)
sid: resolved (fixed in 6.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/50cbb9d195c197af671869c8cadce3bd483735a0https://git.kernel.org/stable/c/8284a79136c384059e85e278da2210b809730287https://git.kernel.org/stable/c/893cb3c3513cf661a0ff45fe0cfa83fe27131f76https://git.kernel.org/stable/c/89a4d1a89751a0fbd520e64091873e19cc0979e8https://git.kernel.org/stable/c/acaee227cf79c45a5d2d49c3e9a66333a462802chttps://git.kernel.org/stable/c/cd66733932399475fe933cb3ec03e687ed401462https://git.kernel.org/stable/c/f718863aca469a109895cb855e6b81fff4827d71
2025-09-16
Published