Vulnerability Name: | CVE-2023-32233 (CCN-254654) | ||||||||||||
Assigned: | 2023-05-08 | ||||||||||||
Published: | 2023-05-08 | ||||||||||||
Updated: | 2023-07-27 | ||||||||||||
Summary: | Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by a use-after-free flaw in Netfilter nf_tables when processing batch requests. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges as root. | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2023-32233 Source: cve@mitre.org Type: UNKNOWN cve@mitre.org Source: cve@mitre.org Type: UNKNOWN cve@mitre.org Source: cve@mitre.org Type: Issue Tracking, Mitigation, Third Party Advisory cve@mitre.org Source: XF Type: UNKNOWN linux-kernel-cve202332233-priv-esc(254654) Source: cve@mitre.org Type: Mailing List, Patch cve@mitre.org Source: CCN Type: Linux Kernel GIT Repository netfilter: nf_tables: deactivate anonymous set from preparation phase Source: cve@mitre.org Type: Patch cve@mitre.org Source: cve@mitre.org Type: UNKNOWN cve@mitre.org Source: cve@mitre.org Type: UNKNOWN cve@mitre.org Source: cve@mitre.org Type: Issue Tracking cve@mitre.org Source: CCN Type: oss-sec Mailing List, Mon, 8 May 2023 16:58:20 +0100 [CVE-2023-32233] Linux kernel use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary reads and writes in kernel memory Source: cve@mitre.org Type: UNKNOWN cve@mitre.org Source: cve@mitre.org Type: Third Party Advisory cve@mitre.org Source: cve@mitre.org Type: Mailing List, Patch, Third Party Advisory cve@mitre.org | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |