CVE-2023-6111
published 2023-11-14CVE-2023-6111: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.32%
24.0th percentile
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times.
We recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | kernel | >= 6.6 < 6.7 | 6.7 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.5.13-1 | 6.5.13-1 |
| linux | linux_kernel | >= 0 < 6.5.13-1 | 6.5.13-1 |
| linux | linux_kernel | >= 5.15.134 < 5.15.140 | 5.15.140 |
| linux | linux_kernel | >= 6.1.56 < 6.1.64 | 6.1.64 |
| linux | linux_kernel | >= 6.5.6 < 6.5.13 | 6.5.13 |
| linux | linux_kernel | >= 6.6 < 6.6.3 | 6.6.3 |
| msrc | azl3_kernel_6.6.29.1-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_kernel_6.6.47.1-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_hyperv-daemons_5.15.143.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OEM) vulnerability
vendor_ubuntu·2024-01-10
CVE-2023-6111 Linux kernel (OEM) vulnerability
Title: Linux kernel (OEM) vulnerability
Summary: The system could be made to crash or run programs as an administrator.
Lonial Con discovered that the netfilter subsystem in the Linux kernel did
not properly handle an expired catchall element in some situations, leading
to a use-after-free vulnerability. A local attacker could use this to cause
a denial of service (system crash) or possibly execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapacka
Microsoft
Use-after-free in Linux kernel's netfilter: nf_tables component
vendor_msrc·2023-11-14·CVSS 7.8
CVE-2023-6111 [HIGH] CWE-416 Use-after-free in Linux kernel's netfilter: nf_tables component
Use-after-free in Linux kernel's netfilter: nf_tables component
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: htt
Red Hat
kernel: netfilter: use-after-free when removing catchall element in GC sync path
vendor_redhat·2023-11-14·CVSS 7.8
CVE-2023-6111 [HIGH] CWE-416 kernel: netfilter: use-after-free when removing catchall element in GC sync path
kernel: netfilter: use-after-free when removing catchall element in GC sync path
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times.
We recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630.
A use-after-free flaw was found in the Linux kernel's netfilter functionality. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.
Statement: Red Hat Enterprise Linux is not affected by this CVE, as the nf_tables GC transaction API and related upstr
Debian
CVE-2023-6111: linux - A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables compon...
vendor_debian·2023·CVSS 7.8
CVE-2023-6111 [HIGH] CVE-2023-6111: linux - A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables compon...
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times. We recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved
forky: resolved (fixed in 6.5.13-1)
sid: resolved (fixed in 6.5.13-1)
trixie: resolved (fixed in 6.5.13-1)
OSV
CVE-2023-6111: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation
osv·2023-11-14·CVSS 7.8
CVE-2023-6111 [HIGH] CVE-2023-6111: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times. We recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630.
GHSA
GHSA-xgr2-4f4q-m3p9: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation
ghsa_unreviewed·2023-11-14
CVE-2023-6111 [HIGH] CWE-416 GHSA-xgr2-4f4q-m3p9: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times.
We recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93995bf4af2c5a99e2a87f0cd5ce547d31eb7630https://kernel.dance/93995bf4af2c5a99e2a87f0cd5ce547d31eb7630https://lists.fedoraproject.org/archives/list/[email protected]/message/3OXWBKK7RTQOGGDLQGCZFS753VLGS2GD/https://lists.fedoraproject.org/archives/list/[email protected]/message/3S55P23EYAWDHXZPJEVTGIRZZRICYI3Z/https://lists.fedoraproject.org/archives/list/[email protected]/message/IG6IF3FUY7LVZJMFRPANAU4L4PSJ3ESQ/https://lists.fedoraproject.org/archives/list/[email protected]/message/YQ7JVDEDZV5SNHG5EW7RHKK2ZN56HSGB/https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93995bf4af2c5a99e2a87f0cd5ce547d31eb7630https://kernel.dance/93995bf4af2c5a99e2a87f0cd5ce547d31eb7630https://lists.fedoraproject.org/archives/list/[email protected]/message/3OXWBKK7RTQOGGDLQGCZFS753VLGS2GD/https://lists.fedoraproject.org/archives/list/[email protected]/message/3S55P23EYAWDHXZPJEVTGIRZZRICYI3Z/https://lists.fedoraproject.org/archives/list/[email protected]/message/IG6IF3FUY7LVZJMFRPANAU4L4PSJ3ESQ/https://lists.fedoraproject.org/archives/list/[email protected]/message/YQ7JVDEDZV5SNHG5EW7RHKK2ZN56HSGB/
2023-11-14
Published