CVE-2023-1095
Summary
| CVE | CVE-2023-1095 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-28 23:15:00 UTC |
| Updated | 2023-03-06 14:41:00 UTC |
| Description | In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction object. nft_trans_destroy() calls list_del(), but the transaction was never placed on a list -- the list head is all zeroes, this results in a NULL pointer dereference. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 2173973 – (CVE-2023-1095) CVE-2023-1095 kernel: netfilter: NULL pointer dereference in nf_tables due to zeroed list head |
MISC |
bugzilla.redhat.com |
|
| netfilter: nf_tables: fix null deref due to zeroed list head · torvalds/linux@5800778 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160525 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12232)
- 181693 Debian Security Update for linux (CVE-2023-1095)
- 199295 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6031-1)
- 199560 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-6001-1)
- 199568 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-6013-1)
- 199577 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6014-1)
- 242147 Red Hat Update for kernel (RHSA-2023:5628)
- 242151 Red Hat Update for kernel security (RHSA-2023:5627)
- 242343 Red Hat Update for kernel (RHSA-2023:6813)
- 378468 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-20230042)
- 378473 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0021)
- 378512 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0042)
- 378710 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0079)
- 390276 Oracle VM Server for x86 Security Update for kernel (OVMSA-2023-0007)
- 672802 EulerOS Security Update for kernel (EulerOS-SA-2023-1551)
- 672981 EulerOS Security Update for kernel (EulerOS-SA-2023-1848)
- 673005 EulerOS Security Update for kernel (EulerOS-SA-2023-1873)
- 673074 EulerOS Security Update for kernel (EulerOS-SA-2023-2193)
- 673117 EulerOS Security Update for kernel (EulerOS-SA-2023-2152)
- 673121 EulerOS Security Update for kernel (EulerOS-SA-2023-2296)
- 673157 EulerOS Security Update for kernel (EulerOS-SA-2023-2272)
- 753901 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:1803-1)
- 753902 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:1800-1)
- 753903 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:1801-1)
- 753905 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:1811-1)
- 753914 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:1848-1)
- 754023 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:2232-1)
- 755851 SUSE Enterprise Linux Security Update for the linux kernel (SUSE-SU-2023:2646-1)
- 905712 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13822)
- 905729 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13808)
- 906554 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13808-1)
- 906605 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13808-3)
- 906688 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13822-3)
- 906798 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (13808-5)