CVE-2023-3390
Summary
| CVE | CVE-2023-3390 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-28 21:15:00 UTC |
| Updated | 2024-03-27 14:11:00 UTC |
| Description | A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97. |
Risk And Classification
Problem Types: CWE-416
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| kernel.dance/1240eb93f0616b21c675416516ff3d74798fdc97 | MISC | kernel.dance | |
| Kernel Live Patch Security Notice LSN-0097-1 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| kernel/git/stable/linux.git - Linux kernel stable tree | MISC | git.kernel.org | |
| lists.debian.org/debian-lts-announce/2024/01/msg00004.html | lists.debian.org | Third Party Advisory, VDB Entry | |
| Debian -- Security Information -- DSA-5461-1 linux | MISC | www.debian.org | |
| [SECURITY] [DLA 3512-1] linux-5.10 security update | MISC | lists.debian.org | |
| Debian -- Security Information -- DSA-5448-1 linux | MISC | www.debian.org | |
| CVE-2023-3390 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160912 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-5069)
- 160948 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-12839)
- 199604 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6246-1)
- 199608 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6250-1)
- 199612 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6255-1)
- 199613 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6251-1)
- 199615 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6252-1)
- 199617 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6254-1)
- 199618 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6260-1)
- 199623 Ubuntu Security Notification for Linux kernel (IoT) Vulnerabilities (USN-6261-1)
- 199651 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6285-1)
- 199764 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6385-1)
- 242062 Red Hat Update for kpatch-patch (RHSA-2023:5221)
- 242068 Red Hat Update for kernel (RHSA-2023:5238)
- 242070 Red Hat Update for kernel security (RHSA-2023:5244)
- 242073 Red Hat Update for kpatch-patch (RHSA-2023:5235)
- 242075 Red Hat Update for kernel-rt (RHSA-2023:5255)
- 243050 Red Hat Update for kernel (RHSA-2024:1250)
- 243053 Red Hat Update for kernel live patch module (RHSA-2024:1253)
- 243055 Red Hat Update for kernel (RHSA-2024:1268)
- 243057 Red Hat Update for kpatch-patch (RHSA-2024:1278)
- 243058 Red Hat Update for kernel-rt (RHSA-2024:1269)
- 243062 Red Hat Update for kernel-rt (RHSA-2024:1306)
- 355591 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-024
- 355632 Amazon Linux Security Advisory for kernel : ALAS2023-2023-251
- 356157 Amazon Linux Security Advisory for kernel : ALAS-2023-1827
- 6000008 Debian Security Update for linux (DSA 5461-1)
- 6000130 Debian Security Update for linux-5.10 (DLA 3512-1)
- 6000207 Debian Security Update for linux (DSA 5448-1)
- 6000429 Debian Security Update for linux (DLA 3710-1)
- 6140184 AWS Bottlerocket Security Update for kernel (GHSA-6p9w-cr65-j5c5)
- 673354 EulerOS Security Update for kernel (EulerOS-SA-2023-2843)
- 673372 EulerOS Security Update for kernel (EulerOS-SA-2023-2787)
- 673449 EulerOS Security Update for kernel (EulerOS-SA-2023-2898)
- 673496 EulerOS Security Update for kernel (EulerOS-SA-2023-2860)
- 673498 EulerOS Security Update for kernel (EulerOS-SA-2023-3132)
- 673604 EulerOS Security Update for kernel (EulerOS-SA-2023-2811)
- 673970 EulerOS Security Update for kernel (EulerOS-SA-2023-2879)
- 755135 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 5 for SLE 15 SP4) (SUSE-SU-2023:4166-1)
- 755140 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 1 for SLE 15 SP5) (SUSE-SU-2023:4175-1)
- 755154 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 3 for SLE 15 SP4) (SUSE-SU-2023:4201-1)
- 755168 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 33 for SLE 15 SP3) (SUSE-SU-2023:4219-1)
- 755180 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 33 for SLE 15 SP2) (SUSE-SU-2023:4245-1)
- 755184 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 29 for SLE 15 SP3) (SUSE-SU-2023:4239-1)
- 755186 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 4 for SLE 15 SP4) (SUSE-SU-2023:4267-1)
- 755192 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 7 for SLE 15 SP4) (SUSE-SU-2023:4285-1)
- 755194 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 34 for SLE 15 SP2) (SUSE-SU-2023:4279-1)
- 755210 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 8 for SLE 15 SP4) (SUSE-SU-2023:4308-1)
- 755212 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 0 for SLE 15 SP5) (SUSE-SU-2023:4326-1)
- 907181 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27346-1)
- 941249 AlmaLinux Security Update for kernel (ALSA-2023:5069)
- 941254 AlmaLinux Security Update for kernel-rt (ALSA-2023:5091)
- 941276 AlmaLinux Security Update for kernel (ALSA-2023:5244)
- 961015 Rocky Linux Security Update for kernel-rt (RLSA-2023:5091)
- 961022 Rocky Linux Security Update for kernel (RLSA-2023:5244)