A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.
2023-07-31T17:15:10.203
2024-11-21T08:34:12.390
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 5.10.188 | Yes |
Operating System | linux | linux_kernel | < 5.15.123 | Yes |
Operating System | linux | linux_kernel | < 6.1.42 | Yes |
Operating System | linux | linux_kernel | < 6.4.7 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux | 9.0 | Yes |
Hardware | netapp | h300s | - | Yes |
Hardware | netapp | h410s | - | Yes |
Hardware | netapp | h500s | - | Yes |
Hardware | netapp | h700s | - | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |
Operating System | debian | debian_linux | 12.0 | Yes |