CVE-2023-6622NULL Pointer Dereference in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 8
Latest updateFeb 23

Description

A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debianlinux/linux_kernel< 6.1.69-1+2
NVDlinux/linux_kernel5.116.6+1

Also affects: Enterprise Linux 8.0, 9.0, Fedora 38, 39

Patches

🔴Vulnerability Details

3
CVEList
Kernel: null pointer dereference vulnerability in nft_dynset_init()2023-12-08
GHSA
GHSA-cjq9-mv23-7rh6: A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset2023-12-08
OSV
CVE-2023-6622: A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset2023-12-08

📋Vendor Advisories

11
Ubuntu
Linux kernel (Azure) vulnerabilities2024-02-23
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-02-15
Ubuntu
Linux kernel (Azure) vulnerabilities2024-02-15
Ubuntu
Linux kernel (OEM) vulnerabilities2024-02-15
Ubuntu
Linux kernel vulnerabilities2024-02-14

💬Community

1
Bugzilla
CVE-2023-6622 kernel: null pointer dereference vulnerability in nft_dynset_init()2023-12-08
CVE-2023-6622 — NULL Pointer Dereference in Kernel | cvebase