Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-4244
HistorySep 06, 2023 - 2:15 p.m.

Race condition

2023-09-0614:15:00
PRIOn knowledge base
www.prio-n.com
7
race condition
use-after-free
vulnerability
netfilter
local privilege escalation
linux kernel
nf_tables
reference counter
garbage collection
upgrade technique
nvd

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A use-after-free vulnerability in the Linux kernel’s netfilter: nf_tables component can be exploited to achieve local privilege escalation.

Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability.

We recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8.

CPENameOperatorVersion
debian_linuxeq10.0
linux_kernellt6.5