Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-3390


A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97.


Published

2023-06-28T21:15:10.447

Last Modified

2024-11-21T08:17:09.960

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-416
  • Type: Primary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel < 4.14.322 Yes
Operating System linux linux_kernel < 4.19.291 Yes
Operating System linux linux_kernel < 5.4.251 Yes
Operating System linux linux_kernel < 5.10.188 Yes
Operating System linux linux_kernel < 5.15.118 Yes
Operating System linux linux_kernel < 6.1.35 Yes
Operating System linux linux_kernel < 6.3.9 Yes
Hardware netapp h300s - Yes
Hardware netapp h410c - Yes
Hardware netapp h410s - Yes
Hardware netapp h500s - Yes
Hardware netapp h700s - Yes

References