F5-K000139430: Use After Free
A use-after-free vulnerability in the Linux kernel's netfilter: nftables component can be exploited to achieve local privilege escalation. The nftverdictinit() function allows positive values as drop error within the hook verdict, and hence the nfhookslow() function can cause a double free vulnerability when NFDROP is issued with a drop error which resembles NFACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000139430?
The severity of F5-K000139430 is critical due to its potential for local privilege escalation.
How do I fix F5-K000139430?
To fix F5-K000139430, update to F5OS-A version 1.8.0 or F5OS-C version 1.8.0.
What systems are affected by F5-K000139430?
F5-K000139430 affects specific versions of F5OS-A and F5OS-C running earlier than the required remedy versions.
What is the nature of the vulnerability in F5-K000139430?
F5-K000139430 is a use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component.
Can F5-K000139430 lead to remote exploitation?
F5-K000139430 is a local privilege escalation vulnerability and does not lead to remote exploitation.