Lucene search

K
cveGoogleCVE-2023-3390
HistoryJun 28, 2023 - 9:15 p.m.

CVE-2023-3390

2023-06-2821:15:10
CWE-416
Google
web.nvd.nist.gov
291
20
cve-2023-3390
linux kernel
netfilter
vulnerability
privilege escalation
nvd
security fix

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

5.1%

A use-after-free vulnerability was found in the Linux kernel’s netfilter subsystem in net/netfilter/nf_tables_api.c.

Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue.

We recommend upgrading past commitΒ 1240eb93f0616b21c675416516ff3d74798fdc97.

Affected configurations

Nvd
Vulners
Node
linuxlinux_kernelRange3.16–4.14.322
OR
linuxlinux_kernelRange4.15–4.19.291
OR
linuxlinux_kernelRange4.20–5.4.251
OR
linuxlinux_kernelRange5.5–5.10.188
OR
linuxlinux_kernelRange5.11–5.15.118
OR
linuxlinux_kernelRange5.16–6.1.35
OR
linuxlinux_kernelRange6.2–6.3.9
Node
netapph300sMatch-
OR
netapph410cMatch-
OR
netapph410sMatch-
OR
netapph500sMatch-
OR
netapph700sMatch-
VendorProductVersionCPE
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
netapph300s-cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
netapph410c-cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
netapph410s-cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
netapph500s-cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
netapph700s-cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "packageName": "kernel",
    "product": "Linux Kernel",
    "repo": "https://git.kernel.org",
    "vendor": "Linux",
    "versions": [
      {
        "lessThan": "6.4",
        "status": "affected",
        "version": "3.16",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

5.1%