Review reviewHigh

CVE-2023-54035

Linux

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix underflow in chain reference counter Set element addition error path decrements reference counter on chains twice: once on element release and again via nft_data_release(). Then, d6b478666ffa ("netfilter: nf_tables: fix underflow in object reference counter") incorrectly fixed this by removing the stateful object reference count decrement. Restore the stateful object decrement as in b91d90368837 ("netfilter: nf_tables: fix leaking object reference count") and let nft_data_release() decrement the ch...

CVSS
7.8
EPSS
0.12%
2.50% percentile
CISA KEV
Not listed
Published
2025.12.24
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.12%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix underflow in chain reference counter Set element addition error path decrements reference counter on chains twice: once on element release and again via nft_data_release(). Then, d6b478666ffa ("netfilter: nf_tables: fix underflow in object reference counter") incorrectly fixed this by removing the stateful object reference count decrement. Restore the stateful object decrement as in b91d90368837 ("netfilter: nf_tables: fix leaking object reference count") and let nft_data_release() decrement the ch...

Affected product and versions

Product
Linux
Affected versions
>= 35651fde1a7bb54dde0a46d35cd0d7136869ae86 < b068314fd8ce751a7f906e55bb90f3551815f1a0, >= 628bd3e49cba1c066228e23d71a852c23e26da73 < 9c959671abc7d4ffdf34eed10c64492d43cb6a3c, >= 628bd3e49cba1c066228e23d71a852c23e26da73 < b389139f12f287b8ed2e2628b72df89a081f0b59, >= bc9f791d2593f17e39f87c6e2b3a36549a3705b1, >= 3c7ec098e3b588434a8b07ea9b5b36f04cef1f50, >= a136b7942ad2a50de708f76ea299ccb45ac7a7f9, >= 25aa2ad37c2162be1c0bc4fe6397f7e4c13f00f8, >= d60be2da67d172aecf866302c91ea11533eca4d9, >= dc7cdf8cbcbf8b13de1df93f356ec04cdeef5c41, >= 4.19.316 < 4.20, >= 5.4.262 < 5.5, >= 5.10.188 < 5.11, >= 5.15.121 < 5.16, >= 6.3.10 < 6.4, >= 6.4
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2023-54035 — Linux | SECUFOCUS NOW