Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-4015
HistoryAug 03, 2023 - 12:00 a.m.

CVE-2023-4015

2023-08-0300:00:00
ubuntu.com
ubuntu.com
36
linux kernel
netfilter
nf_tables
use-after-free
vulnerability
local privilege escalation
upgrading
commit 0a771f7b266b02d262900c75f1e175c7fe76fec2

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

A use-after-free vulnerability in the Linux kernel’s netfilter: nf_tables
component can be exploited to achieve local privilege escalation. On an
error when building a nftables rule, deactivating immediate expressions in
nft_immediate_deactivate() can lead unbinding the chain and objects be
deactivated but later used. We recommend upgrading past commit
0a771f7b266b02d262900c75f1e175c7fe76fec2.

Notes

Author Note
Priority reason: By using unprivileged user namespaces, this can be exploited to achieve local privilege escalation.
rodrigo-zaiden Google kCTF submission
Rows per page:
1-10 of 421

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%