CVE-2023-32233 Information

Description

In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

Reference

https://github.com/torvalds/linux/commit/c1592a89942e9678f7d9c8030efa777c0d57edab https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c1592a89942e9678f7d9c8030efa777c0d57edab https://www.openwall.com/lists/oss-security/2023/05/08/4 https://bugzilla.redhat.com/show_bug.cgi?id=2196105 https://news.ycombinator.com/item?id=35879660

Share on: