Review reviewHigh

CVE-2023-54243

Linux

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix table blob use-after-free We are not allowed to return an error at this point. Looking at the code it looks like ret is always 0 at this point, but its not. t = find_table_lock(net, repl->name, &ret, &ebt_mutex); ... this can return a valid table, with ret != 0. This bug causes update of table->private with the new blob, but then frees the blob right away in the caller. Syzbot report: BUG: KASAN: vmalloc-out-of-bounds in __ebt_unregister_table+0xc00/0xcd0 net/bridge/netfilter/ebtables.c:1168 Read of...

CVSS
7.8
EPSS
0.13%
3.01% percentile
CISA KEV
Not listed
Published
2025.12.30
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.13%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix table blob use-after-free We are not allowed to return an error at this point. Looking at the code it looks like ret is always 0 at this point, but its not. t = find_table_lock(net, repl->name, &ret, &ebt_mutex); ... this can return a valid table, with ret != 0. This bug causes update of table->private with the new blob, but then frees the blob right away in the caller. Syzbot report: BUG: KASAN: vmalloc-out-of-bounds in __ebt_unregister_table+0xc00/0xcd0 net/bridge/netfilter/ebtables.c:1168 Read of...

Affected product and versions

Product
Linux
Affected versions
>= c58dd2dd443c26d856a168db108a0cd11c285bf3 < 9060abce3305ab2354c892c09d5689df51486df5, >= c58dd2dd443c26d856a168db108a0cd11c285bf3 < dbb3cbbf03b3c52cb390fabec357f1e4638004f5, >= c58dd2dd443c26d856a168db108a0cd11c285bf3 < 3dd6ac973351308d4117eda32298a9f1d68764fd, >= c58dd2dd443c26d856a168db108a0cd11c285bf3 < cda0e0243bd3c04008fcd37a46b0269fb3c49249, >= c58dd2dd443c26d856a168db108a0cd11c285bf3 < e58a171d35e32e6e8c37cfe0e8a94406732a331f, >= a3bc0f8ea439762aa62d40a295157410498cbea7, >= 8ed40c122919cd79bc3c059e5864e5e7d9d455f0, >= c5e4ef499cfc78de45a4f01b8c557b5964d77c53, >= f34728610b2a8c7b9864f9404f2884c17f6fca5c, >= 8b5740915a9faa8b1fa9166193a33e2a9ae30ec6, >= 3.2.60 < 3.3, >= 3.4.91 < 3.5, >= 3.10.41 < 3.11, >= 3.12.21 < 3.13, >= 3.14.5 < 3.15, >= 3.15
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available