CVE-2023-4004: Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()

Published Jul 24, 2023
·
Updated

A flaw in the Linux Kernel found. Improper element removal in function nftpipaporemove when insert an element without a NFTSETEXTKEYEND that can lead to use-after-free.

Reference: https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230719190824.21196-1-fw@strlen.de/

Other sources

A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nftpipaporemove function with the element, without a NFTSETEXTKEYEND. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.

Launchpad

Linux Kernel could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the nftpipaporemove function in the netfilter. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges or cause the system to crash.

IBM

Affected Software

22 affected componentsFixes available
redhat/kernel<6.5
6.5
IBM Storage Protect Plus vSnap<=10.1
Linux Linux kernel=6.5-rc1
Linux Linux kernel<6.5
Linux Linux kernel=6.5-rc2
Linux Linux kernel=6.5-rc3
Linux Linux kernel=6.5-rc4
Fedoraproject Fedora=38
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
Linux Linux kernel>=5.6<5.10.188
Linux Linux kernel>=5.11<5.15.123
Linux Linux kernel>=5.16<6.1.42
Linux Linux kernel>=6.2<6.4.7
NetApp H300s
NetApp H410s
NetApp H500s
NetApp H700s
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Debian Debian Linux=12.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Remediation

Mitigation

If not needed, disable the ability for unprivileged users to create namespaces. To do this temporarily, do: sudo sysctl -w kernel.unprivileged_userns_clone=0 To disable across reboots, do: echo kernel.unprivileged_userns_clone=0 | \ sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf

Event History

Jul 24, 2023
Data Sourced
via Red Hat·08:33 PM
DescriptionSeverityAffected Software
Jul 31, 2023
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:24 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·02:14 PM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-4004?

CVE-2023-4004 has a high severity rating due to its potential to cause use-after-free vulnerabilities in the Linux Kernel.

2

How do I fix CVE-2023-4004?

To fix CVE-2023-4004, update the Linux Kernel to a version that includes the patch addressing this vulnerability.

3

Which systems are affected by CVE-2023-4004?

CVE-2023-4004 affects various systems including IBM Storage Protect Plus vSnap, Red Hat Enterprise Linux, and several versions of the Linux Kernel.

4

Can CVE-2023-4004 lead to data loss?

Yes, CVE-2023-4004 can lead to data loss as it can result in memory corruption due to use-after-free errors.

5

What is the recommended action for servers running Linux Kernel version 6.5 or lower for CVE-2023-4004?

It is recommended to upgrade to a patched version of the Linux Kernel to mitigate the risks associated with CVE-2023-4004.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203