CVE-2023-53304NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix overlap expiration walk The lazy gc on insert that should remove timed-out entries fails to release the other half of the interval, if any. Can be reproduced with tests/shell/testcases/sets/0044interval_overlap_0 in nftables.git and kmemleak enabled kernel. Second bug is the use of rbe_prev vs. prev pointer. If rbe_prev() returns NULL after at least one iteration, rbe_prev points to element tha

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.10.1665.10.190+5
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linux7ab87a326f20c52ff4d9972052d085be951c704b8284a79136c384059e85e278da2210b809730287+7
debiandebian/linux< linux 6.1.52-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53304: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix overlap expiration walk The lazy gc on insert that2025-09-16
GHSA
GHSA-phm5-wwmp-pqvr: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix overlap expiration walk The lazy gc on insert tha2025-09-16

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Denial of Service in netfilter due to improper garbage collection2025-09-16
Debian
CVE-2023-53304: linux - In the Linux kernel, the following vulnerability has been resolved: netfilter: ...2023
CVE-2023-53304 — NULL Pointer Dereference in Linux | cvebase