CVE-2023-32233
68Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 7.8epss 13%
from disclosure to weapon8 days
Published on NVDMay 8
1st PoC+8d
VulnCheck+578d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 5
vulncheckvulncheck.com/xdb/c076df76f476unverifiedvulncheckvulncheck.com/xdb/814294d50f42unverifiedvulncheckvulncheck.com/xdb/fb9759f7ce7cunverifiedvulncheckvulncheck.com/xdb/fd0f7c34fb56unverifiedvulncheckvulncheck.com/xdb/6f75b3643b15unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/173087/Kernel-Live-Patch-Security-Notice-LSN-0095-1.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=2196105https://github.com/torvalds/linux/commit/c1592a89942e9678f7d9c8030efa777c0d57edabhttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c1592a89942e9678f7d9c8030efa777c0d57edabhttps://lists.debian.org/debian-lts-announce/2023/06/msg00008.htmlhttps://lists.debian.org/debian-lts-announce/2023/07/msg00030.htmlhttps://news.ycombinator.com/item?id=35879660https://security.netapp.com/advisory/ntap-20230616-0002/https://www.debian.org/security/2023/dsa-5402https://www.openwall.com/lists/oss-security/2023/05/08/4http://www.openwall.com/lists/oss-security/2023/05/15/5