First published: Wed Jan 31 2024(Updated: )
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
Credit: cve-coordination@google.com cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 F5OS-A | =1.7.0>=1.5.0<=1.5.2 | |
F5 F5OS-C | >=1.6.0<=1.6.2>=1.5.0<=1.5.1 | |
IBM QRadar SIEM | <=7.5 - 7.5.0 UP8 IF01 | |
Linux Linux kernel | >=3.15<5.15.149 | |
Linux Linux kernel | >=6.1<6.1.76 | |
Linux Linux kernel | >=6.2<6.6.15 | |
Linux Linux kernel | >=6.7<6.7.3 | |
Linux Linux kernel | =6.8-rc1 | |
Fedoraproject Fedora | =39 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux For Ibm Z Systems | =7.0_s390x | |
Redhat Enterprise Linux For Power Big Endian | =7.0_ppc64 | |
Redhat Enterprise Linux For Power Little Endian | =7.0_ppc64le | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Debian Debian Linux | =10.0 | |
All of | ||
Netapp A250 Firmware | ||
Netapp A250 | ||
All of | ||
Netapp 500f Firmware | ||
Netapp 500f | ||
All of | ||
Netapp C250 Firmware | ||
Netapp C250 | ||
redhat/kernel | <6.8 | 6.8 |
ubuntu/linux | <4.15.0-223.235 | 4.15.0-223.235 |
ubuntu/linux | <5.4.0-174.193 | 5.4.0-174.193 |
ubuntu/linux | <5.15.0-101.111 | 5.15.0-101.111 |
ubuntu/linux | <6.5.0-26.26 | 6.5.0-26.26 |
ubuntu/linux | <6.8~ | 6.8~ |
ubuntu/linux | <4.4.0-252.286 | 4.4.0-252.286 |
ubuntu/linux-aws | <4.15.0-1166.179 | 4.15.0-1166.179 |
ubuntu/linux-aws | <5.4.0-1121.131 | 5.4.0-1121.131 |
ubuntu/linux-aws | <5.15.0-1056.61 | 5.15.0-1056.61 |
ubuntu/linux-aws | <6.5.0-1016.16 | 6.5.0-1016.16 |
ubuntu/linux-aws | <4.4.0-1129.135 | 4.4.0-1129.135 |
ubuntu/linux-aws | <6.8~ | 6.8~ |
ubuntu/linux-aws | <4.4.0-1167.182 | 4.4.0-1167.182 |
ubuntu/linux-aws-5.15 | <5.15.0-1056.61~20.04.1 | 5.15.0-1056.61~20.04.1 |
ubuntu/linux-aws-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-aws-5.4 | <5.4.0-1121.131~18.04.1 | 5.4.0-1121.131~18.04.1 |
ubuntu/linux-aws-5.4 | <6.8~ | 6.8~ |
ubuntu/linux-aws-6.5 | <6.5.0-1016.16~22.04.1 | 6.5.0-1016.16~22.04.1 |
ubuntu/linux-aws-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-aws-fips | <6.8~ | 6.8~ |
ubuntu/linux-aws-hwe | <6.8~ | 6.8~ |
ubuntu/linux-aws-hwe | <4.15.0-1166.179~16.04.1 | 4.15.0-1166.179~16.04.1 |
ubuntu/linux-azure | <5.4.0-1126.133 | 5.4.0-1126.133 |
ubuntu/linux-azure | <5.15.0-1059.67 | 5.15.0-1059.67 |
ubuntu/linux-azure | <6.5.0-1017.17 | 6.5.0-1017.17 |
ubuntu/linux-azure | <4.15.0-1175.190~14.04.1 | 4.15.0-1175.190~14.04.1 |
ubuntu/linux-azure | <6.8~ | 6.8~ |
ubuntu/linux-azure | <4.15.0-1175.190~16.04.1 | 4.15.0-1175.190~16.04.1 |
ubuntu/linux-azure-4.15 | <4.15.0-1175.190 | 4.15.0-1175.190 |
ubuntu/linux-azure-4.15 | <6.8~ | 6.8~ |
ubuntu/linux-azure-5.15 | <5.15.0-1059.67~20.04.1 | 5.15.0-1059.67~20.04.1 |
ubuntu/linux-azure-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-azure-5.4 | <5.4.0-1126.133~18.04.1 | 5.4.0-1126.133~18.04.1 |
ubuntu/linux-azure-5.4 | <6.8~ | 6.8~ |
ubuntu/linux-azure-6.5 | <6.5.0-1017.17~22.04.1 | 6.5.0-1017.17~22.04.1 |
ubuntu/linux-azure-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-azure-fde | <5.15.0-1059.67.1 | 5.15.0-1059.67.1 |
ubuntu/linux-azure-fde | <6.8~ | 6.8~ |
ubuntu/linux-azure-fde-5.15 | <5.15.0-1059.67~20.04.1.1 | 5.15.0-1059.67~20.04.1.1 |
ubuntu/linux-azure-fde-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-azure-fips | <6.8~ | 6.8~ |
ubuntu/linux-bluefield | <5.4.0-1081.88 | 5.4.0-1081.88 |
ubuntu/linux-bluefield | <6.8~ | 6.8~ |
ubuntu/linux-fips | <6.8~ | 6.8~ |
ubuntu/linux-gcp | <5.4.0-1125.134 | 5.4.0-1125.134 |
ubuntu/linux-gcp | <5.15.0-1054.62 | 5.15.0-1054.62 |
ubuntu/linux-gcp | <6.5.0-1016.16 | 6.5.0-1016.16 |
ubuntu/linux-gcp | <6.8~ | 6.8~ |
ubuntu/linux-gcp | <4.15.0-1160.177~16.04.1 | 4.15.0-1160.177~16.04.1 |
ubuntu/linux-gcp-4.15 | <4.15.0-1160.177 | 4.15.0-1160.177 |
ubuntu/linux-gcp-4.15 | <6.8~ | 6.8~ |
ubuntu/linux-gcp-5.15 | <5.15.0-1054.62~20.04.1 | 5.15.0-1054.62~20.04.1 |
ubuntu/linux-gcp-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-gcp-5.4 | <5.4.0-1125.134~18.04.1 | 5.4.0-1125.134~18.04.1 |
ubuntu/linux-gcp-5.4 | <6.8~ | 6.8~ |
ubuntu/linux-gcp-6.5 | <6.5.0-1016.16~22.04.1 | 6.5.0-1016.16~22.04.1 |
ubuntu/linux-gcp-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-gcp-fips | <6.8~ | 6.8~ |
ubuntu/linux-gke | <5.15.0-1053.58 | 5.15.0-1053.58 |
ubuntu/linux-gke | <6.8~ | 6.8~ |
ubuntu/linux-gkeop | <5.4.0-1088.92 | 5.4.0-1088.92 |
ubuntu/linux-gkeop | <5.15.0-1039.45 | 5.15.0-1039.45 |
ubuntu/linux-gkeop | <6.8~ | 6.8~ |
ubuntu/linux-gkeop-5.15 | <5.15.0-1039.45~20.04.1 | 5.15.0-1039.45~20.04.1 |
ubuntu/linux-gkeop-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-hwe | <6.8~ | 6.8~ |
ubuntu/linux-hwe | <4.15.0-223.235~16.04.1 | 4.15.0-223.235~16.04.1 |
ubuntu/linux-hwe-5.15 | <5.15.0-101.111~20.04.1 | 5.15.0-101.111~20.04.1 |
ubuntu/linux-hwe-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-hwe-5.4 | <5.4.0-174.193~18.04.1 | 5.4.0-174.193~18.04.1 |
ubuntu/linux-hwe-5.4 | <6.8~ | 6.8~ |
ubuntu/linux-hwe-6.5 | <6.5.0-26.26~22.04.1 | 6.5.0-26.26~22.04.1 |
ubuntu/linux-hwe-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-ibm | <5.4.0-1068.73 | 5.4.0-1068.73 |
ubuntu/linux-ibm | <5.15.0-1049.52 | 5.15.0-1049.52 |
ubuntu/linux-ibm | <6.8~ | 6.8~ |
ubuntu/linux-ibm-5.15 | <5.15.0-1049.52~20.04.1 | 5.15.0-1049.52~20.04.1 |
ubuntu/linux-ibm-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-ibm-5.4 | <5.4.0-1068.73~18.04.1 | 5.4.0-1068.73~18.04.1 |
ubuntu/linux-ibm-5.4 | <6.8~ | 6.8~ |
ubuntu/linux-intel | <6.8~ | 6.8~ |
ubuntu/linux-intel-iot-realtime | <6.8~ | 6.8~ |
ubuntu/linux-intel-iotg | <5.15.0-1051.57 | 5.15.0-1051.57 |
ubuntu/linux-intel-iotg | <6.8~ | 6.8~ |
ubuntu/linux-intel-iotg-5.15 | <5.15.0-1051.57~20.04.1 | 5.15.0-1051.57~20.04.1 |
ubuntu/linux-intel-iotg-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-iot | <5.4.0-1033.34 | 5.4.0-1033.34 |
ubuntu/linux-iot | <6.8~ | 6.8~ |
ubuntu/linux-kvm | <4.15.0-1150.155 | 4.15.0-1150.155 |
ubuntu/linux-kvm | <5.4.0-1109.116 | 5.4.0-1109.116 |
ubuntu/linux-kvm | <5.15.0-1053.58 | 5.15.0-1053.58 |
ubuntu/linux-kvm | <6.8~ | 6.8~ |
ubuntu/linux-kvm | <4.4.0-1130.140 | 4.4.0-1130.140 |
ubuntu/linux-laptop | <6.5.0-1012.15 | 6.5.0-1012.15 |
ubuntu/linux-laptop | <6.8~ | 6.8~ |
ubuntu/linux-lowlatency | <5.15.0-101.111 | 5.15.0-101.111 |
ubuntu/linux-lowlatency | <6.5.0-26.26.1 | 6.5.0-26.26.1 |
ubuntu/linux-lowlatency | <6.8~ | 6.8~ |
ubuntu/linux-lowlatency-hwe-5.15 | <5.15.0-101.111~20.04.1 | 5.15.0-101.111~20.04.1 |
ubuntu/linux-lowlatency-hwe-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-lowlatency-hwe-6.5 | <6.5.0-26.26.1~22.04.1 | 6.5.0-26.26.1~22.04.1 |
ubuntu/linux-lowlatency-hwe-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-lowlatency-hwe-6.8 | <6.8~ | 6.8~ |
ubuntu/linux-lts-xenial | <4.4.0-252.286~14.04.1 | 4.4.0-252.286~14.04.1 |
ubuntu/linux-lts-xenial | <6.8~ | 6.8~ |
ubuntu/linux-nvidia | <5.15.0-1047.47 | 5.15.0-1047.47 |
ubuntu/linux-nvidia | <6.8~ | 6.8~ |
ubuntu/linux-nvidia-6.5 | <6.5.0-1014.14 | 6.5.0-1014.14 |
ubuntu/linux-nvidia-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-nvidia-6.8 | <6.8~ | 6.8~ |
ubuntu/linux-nvidia-lowlatency | <6.8~ | 6.8~ |
ubuntu/linux-oem-6.1 | <6.1.0-1035.35 | 6.1.0-1035.35 |
ubuntu/linux-oem-6.1 | <6.8~ | 6.8~ |
ubuntu/linux-oem-6.5 | <6.5.0-1018.19 | 6.5.0-1018.19 |
ubuntu/linux-oem-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-oem-6.8 | <6.8~ | 6.8~ |
ubuntu/linux-oracle | <4.15.0-1129.140 | 4.15.0-1129.140 |
ubuntu/linux-oracle | <5.4.0-1120.129 | 5.4.0-1120.129 |
ubuntu/linux-oracle | <5.15.0-1054.60 | 5.15.0-1054.60 |
ubuntu/linux-oracle | <6.5.0-1019.19 | 6.5.0-1019.19 |
ubuntu/linux-oracle | <6.8~ | 6.8~ |
ubuntu/linux-oracle | <4.15.0-1129.140~16.04.1 | 4.15.0-1129.140~16.04.1 |
ubuntu/linux-oracle-5.15 | <5.15.0-1054.60~20.04.1 | 5.15.0-1054.60~20.04.1 |
ubuntu/linux-oracle-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-oracle-5.4 | <5.4.0-1120.129~18.04.1 | 5.4.0-1120.129~18.04.1 |
ubuntu/linux-oracle-5.4 | <6.8~ | 6.8~ |
ubuntu/linux-oracle-6.5 | <6.5.0-1019.19~22.04.1 | 6.5.0-1019.19~22.04.1 |
ubuntu/linux-oracle-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-raspi | <5.4.0-1105.117 | 5.4.0-1105.117 |
ubuntu/linux-raspi | <5.15.0-1049.52 | 5.15.0-1049.52 |
ubuntu/linux-raspi | <6.5.0-1013.16 | 6.5.0-1013.16 |
ubuntu/linux-raspi | <6.8~ | 6.8~ |
ubuntu/linux-raspi-5.4 | <5.4.0-1105.117~18.04.1 | 5.4.0-1105.117~18.04.1 |
ubuntu/linux-raspi-5.4 | <6.8~ | 6.8~ |
ubuntu/linux-raspi-realtime | <6.8~ | 6.8~ |
ubuntu/linux-realtime | <6.8~ | 6.8~ |
ubuntu/linux-riscv | <6.5.0-26.26.1 | 6.5.0-26.26.1 |
ubuntu/linux-riscv | <6.8~ | 6.8~ |
ubuntu/linux-riscv-5.15 | <5.15.0-1052.56~20.04.1 | 5.15.0-1052.56~20.04.1 |
ubuntu/linux-riscv-5.15 | <6.8~ | 6.8~ |
ubuntu/linux-riscv-6.5 | <6.5.0-26.26.1~22.04.1 | 6.5.0-26.26.1~22.04.1 |
ubuntu/linux-riscv-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-riscv-6.8 | <6.8~ | 6.8~ |
ubuntu/linux-starfive | <6.5.0-1010.11 | 6.5.0-1010.11 |
ubuntu/linux-starfive | <6.8~ | 6.8~ |
ubuntu/linux-starfive-6.5 | <6.5.0-1010.11~22.04.1 | 6.5.0-1010.11~22.04.1 |
ubuntu/linux-starfive-6.5 | <6.8~ | 6.8~ |
ubuntu/linux-xilinx-zynqmp | <5.4.0-1040.44 | 5.4.0-1040.44 |
ubuntu/linux-xilinx-zynqmp | <5.15.0-1030.34 | 5.15.0-1030.34 |
ubuntu/linux-xilinx-zynqmp | <6.8~ | 6.8~ |
Linux kernel | ||
debian/linux | 5.10.223-1 6.1.106-3 6.1.99-1 6.10.6-1 6.10.9-1 |
If not needed, disable the ability for unprivileged users to create namespaces. To do this temporarily, do: sudo sysctl -w kernel.unprivileged_userns_clone=0 To disable across reboots, do: echo kernel.unprivileged_userns_clone=0 | \ sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)