CVE-2023-5972
published 2023-11-23CVE-2023-5972: A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
19.5th percentile
A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.5.10-1 (forky) | linux 6.5.10-1 (forky) |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.5.10-1 | 6.5.10-1 |
| linux | linux_kernel | >= 0 < 6.5.10-1 | 6.5.10-1 |
| linux | linux_kernel | 6.2.1 – 6.5.10 | — |
| msrc | cbl2_hyperv-daemons_5.15.143.1-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_debian7.0LOW
vendor_redhat7.0HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-azure vulnerabilities
osv·2024-02-23·CVSS 4.9
CVE-2023-34324 [MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
Marek Marczykowski-Górecki discovered that the Xen event channel
infrastructure implementation in the Linux kernel contained a race
condition. An attacker in a guest VM could possibly use this to cause a
denial of service (paravirtualized device unavailability). (CVE-2023-34324)
Zheng Wang discovered a use-after-free in the Renesas Ethernet AVB driver
in the Linux kernel during device removal. A privileged attacker could use
this to cause a denial of service (system crash). (CVE-2023-35827)
Tom Dohrmann discovered that the Secure Encrypted Virtualization (SEV)
implementation for AMD processors in the Linux kernel contained a race
condition when accessing MMIO registers. A local attacker in a SEV guest VM
could possibly use this to cause a denial of service (s
OSV
linux, linux-aws, linux-gcp, linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
osv·2024-02-07·CVSS 4.9
CVE-2023-34324 [MEDIUM] linux, linux-aws, linux-gcp, linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
linux, linux-aws, linux-gcp, linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
Marek Marczykowski-Górecki discovered that the Xen event channel
infrastructure implementation in the Linux kernel contained a race
condition. An attacker in a guest VM could possibly use this to cause a
denial of service (paravirtualized device unavailability). (CVE-2023-34324)
Zheng Wang discovered a use-after-free in the Renesas Ethernet AVB driver
in the Linux kernel during device removal. A privileged attacker could use
this to cause a denial of service (system crash). (CVE-2023-35827)
Tom Dohrmann discovered that the Secure Encrypted Virtualization (SEV)
implementation for AMD processors in the Linux kernel c
GHSA
GHSA-8jhq-62jp-gh72: A null pointer dereference flaw was found in the nft_inner
ghsa_unreviewed·2023-11-23
CVE-2023-5972 [HIGH] CWE-476 GHSA-8jhq-62jp-gh72: A null pointer dereference flaw was found in the nft_inner
A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.
OSV
CVE-2023-5972: A null pointer dereference flaw was found in the nft_inner
osv·2023-11-23·CVSS 7.8
CVE-2023-5972 [HIGH] CVE-2023-5972: A null pointer dereference flaw was found in the nft_inner
A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2024-02-23·CVSS 4.9
CVE-2023-46862 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Marek Marczykowski-Górecki discovered that the Xen event channel
infrastructure implementation in the Linux kernel contained a race
condition. An attacker in a guest VM could possibly use this to cause a
denial of service (paravirtualized device unavailability). (CVE-2023-34324)
Zheng Wang discovered a use-after-free in the Renesas Ethernet AVB driver
in the Linux kernel during device removal. A privileged attacker could use
this to cause a denial of service (system crash). (CVE-2023-35827)
Tom Dohrmann discovered that the Secure Encrypted Virtualization (SEV)
implementation for AMD processors in the Linux kernel contained a race
condition when accessing MMIO registers. A local
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-02-07·CVSS 4.9
CVE-2023-6531 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Marek Marczykowski-Górecki discovered that the Xen event channel
infrastructure implementation in the Linux kernel contained a race
condition. An attacker in a guest VM could possibly use this to cause a
denial of service (paravirtualized device unavailability). (CVE-2023-34324)
Zheng Wang discovered a use-after-free in the Renesas Ethernet AVB driver
in the Linux kernel during device removal. A privileged attacker could use
this to cause a denial of service (system crash). (CVE-2023-35827)
Tom Dohrmann discovered that the Secure Encrypted Virtualization (SEV)
implementation for AMD processors in the Linux kernel contained a race
condition when accessing MMIO registers. A local attacker
Microsoft
Kernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.c
vendor_msrc·2023-11-14·CVSS 7.8
CVE-2023-5972 [HIGH] CWE-476 Kernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.c
Kernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.c
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required:
Red Hat
kernel: The NFTA_INNER_NUM and NFTA_EXPR_NAME netlink attributes accessed without checking its presence in nft_inner.c
vendor_redhat·2023-10-12·CVSS 7.0
CVE-2023-5972 [HIGH] CWE-476 kernel: The NFTA_INNER_NUM and NFTA_EXPR_NAME netlink attributes accessed without checking its presence in nft_inner.c
kernel: The NFTA_INNER_NUM and NFTA_EXPR_NAME netlink attributes accessed without checking its presence in nft_inner.c
A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.
A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.
Statement: It is Moderate impact, because attack scenario only allows crash of the system (denial of service).
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Ha
Debian
CVE-2023-5972: linux - A null pointer dereference flaw was found in the nft_inner.c functionality of ne...
vendor_debian·2023·CVSS 7.0
CVE-2023-5972 [HIGH] CVE-2023-5972: linux - A null pointer dereference flaw was found in the nft_inner.c functionality of ne...
A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.5.10-1)
sid: resolved (fixed in 6.5.10-1)
trixie: resolved (fixed in 6.5.10-1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2023-5972https://bugzilla.redhat.com/show_bug.cgi?id=2248189https://github.com/torvalds/linux/commit/505ce0630ad5d31185695f8a29dde8d29f28faa7https://github.com/torvalds/linux/commit/52177bbf19e6e9398375a148d2e13ed492b40b80https://access.redhat.com/security/cve/CVE-2023-5972https://bugzilla.redhat.com/show_bug.cgi?id=2248189https://github.com/torvalds/linux/commit/505ce0630ad5d31185695f8a29dde8d29f28faa7https://github.com/torvalds/linux/commit/52177bbf19e6e9398375a148d2e13ed492b40b80
2023-11-23
Published