CVE-2023-5972NULL Pointer Dereference in Kernel

Severity
7.8HIGHNVD
CNA7.0OSV4.9
EPSS
0.0%
top 97.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23
Latest updateFeb 23

Description

A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debianlinux/linux_kernel< 6.5.10-1+1
NVDlinux/linux_kernel6.2.16.5.10+3

Also affects: Fedora 39

Patches

🔴Vulnerability Details

5
OSV
linux-azure vulnerabilities2024-02-23
OSV
linux, linux-aws, linux-gcp, linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-lowlatency-hwe-6.5, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities2024-02-07
GHSA
GHSA-8jhq-62jp-gh72: A null pointer dereference flaw was found in the nft_inner2023-11-23
OSV
CVE-2023-5972: A null pointer dereference flaw was found in the nft_inner2023-11-23
CVEList
Kernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.c2023-11-23

📋Vendor Advisories

5
Ubuntu
Linux kernel (Azure) vulnerabilities2024-02-23
Ubuntu
Linux kernel vulnerabilities2024-02-07
Microsoft
Kernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.c2023-11-14
Red Hat
kernel: The NFTA_INNER_NUM and NFTA_EXPR_NAME netlink attributes accessed without checking its presence in nft_inner.c2023-10-12
Debian
CVE-2023-5972: linux - A null pointer dereference flaw was found in the nft_inner.c functionality of ne...2023

💬Community

1
Bugzilla
CVE-2023-5972 kernel: The NFTA_INNER_NUM and NFTA_EXPR_NAME netlink attributes accessed without checking its presence in nft_inner.c2023-11-06
CVE-2023-5972 — NULL Pointer Dereference in Kernel | cvebase