← Back

CVE-2023-3390

nvd nist
Published: Jun 28, 2023Modified: Jul 22, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97

Affected (12)

1 product
Linux Kernel
5 products
H300s
H410c
H410s
H500s
H700s
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 3.16 to 4.14.322
From 4.15 to 4.19.291
From 4.20 to 5.4.251
From 5.11 to 5.15.118
From 5.16 to 6.1.35
From 5.5 to 5.10.188
From 6.2 to 6.3.9
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
All versions

References (16)

Source: cve-coordination@google.com
Third Party Advisory
Source: cve-coordination@google.com
Third Party AdvisoryVDB Entry
Source: cve-coordination@google.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.