Bug 2237755 - netfilter: nf_tables UAF
Summary: netfilter: nf_tables UAF
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2235312 2237754
TreeView+ depends on / blocked
 
Reported: 2023-09-06 17:51 UTC by juneau
Modified: 2023-10-10 10:29 UTC (History)
37 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2023-09-07 18:07:09 UTC
Embargoed:


Attachments (Terms of Use)

Description juneau 2023-09-06 17:51:12 UTC
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.

Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability.

We recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8.

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3e91b0ebd994635df2346353322ac51ce84ce6d8
https://kernel.dance/3e91b0ebd994635df2346353322ac51ce84ce6d8

Comment 1 Rohit Keshri 2023-09-07 18:02:54 UTC
*** Bug 2235306 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.