Fiche vulnérabilité
CVE-2023-32233 : faille élevée linux linux kernel (CVSS 7.8)
Description
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 8 mai 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- linux linux kernel
- redhat enterprise linux
- netapp hci baseboard management controller
Références
- Fiche CVE-2023-32233 sur le NVD (NIST)
- packetstormsecurity.com/files/173087/Kernel…
- openwall.com/lists/oss-security/2023/05/15/5
- bugzilla.redhat.com/show_bug.cgi
- git.kernel.org/cgit/linux/kernel/git/torvalds/linux…
- github.com/torvalds/linux/commit/c1592a89942e9678f7d9c803…
- lists.debian.org/debian-lts-announce/2023/06/msg00008.html
- lists.debian.org/debian-lts-announce/2023/07/msg00030.html
- news.ycombinator.com/item
- security.netapp.com/advisory/ntap-20230616-0002/
- debian.org/security/2023/dsa-5402
- openwall.com/lists/oss-security/2023/05/08/4