Review reviewHigh

CVE-2023-3390

Linux Linux Kernel, linux kernel, h300s

A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97

CVSS
7.8
EPSS
0.91%
56.7% percentile
CISA KEV
Not listed
Published
2023.06.29
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.91%
Technical severityCVSS 7.8

Vulnerability overview

A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97

Affected product and versions

Product
Linux Linux Kernel, linux kernel, h300s
Affected versions
>= 3.16 < 4.14.322, >= 4.15 < 4.19.291, >= 4.20 < 5.4.251, >= 5.5 < 5.10.188, >= 5.11 < 5.15.118, >= 5.16 < 6.1.35, >= 6.2 < 6.3.9
Fixed versions
4.14.322, 4.19.291, 5.4.251, 5.10.188, 5.15.118, 6.1.35, 6.3.9

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux Kernel, linux kernel, h300s and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2023-3390 — Linux Linux Kernel, linux kernel, h300s | SECUFOCUS NOW