Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-32233


In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.


Published

2023-05-08T20:15:20.267

Last Modified

2025-05-05T16:15:39.637

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-416
  • Type: Secondary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel < 4.14.315 Yes
Operating System linux linux_kernel < 4.19.283 Yes
Operating System linux linux_kernel < 5.4.243 Yes
Operating System linux linux_kernel < 5.10.180 Yes
Operating System linux linux_kernel < 5.15.111 Yes
Operating System linux linux_kernel < 6.1.28 Yes
Operating System linux linux_kernel < 6.2.15 Yes
Operating System linux linux_kernel < 6.3.2 Yes
Operating System redhat enterprise_linux 7.0 Yes
Operating System redhat enterprise_linux 8.0 Yes
Operating System redhat enterprise_linux 9.0 Yes
Application netapp hci_baseboard_management_controller h300s Yes
Application netapp hci_baseboard_management_controller h410c Yes
Application netapp hci_baseboard_management_controller h410s Yes
Application netapp hci_baseboard_management_controller h500s Yes
Application netapp hci_baseboard_management_controller h700s Yes

References