CVE-2023-3777
Summary
| CVE | CVE-2023-3777 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-06 14:15:00 UTC |
| Updated | 2023-10-24 15:01:00 UTC |
| Description | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances.
We recommend upgrading past commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| Debian -- Security Information -- DSA-5492-1 linux |
MISC |
www.debian.org |
|
| Kernel Live Patch Security Notice LSN-0098-1 ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| kernel.dance/6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8 |
MISC |
kernel.dance |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161318 Oracle Enterprise Linux Security Update for kernel (ELSA-2024-12094)
- 161404 Oracle Enterprise Linux Security Update for kernel (ELSA-2024-0461)
- 199764 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6385-1)
- 242759 Red Hat Update for kernel (RHSA-2024:0432)
- 242839 Red Hat Update for kernel (RHSA-2024:0461)
- 242845 Red Hat Update for kernel (RHSA-2024:0448)
- 242846 Red Hat Update for kernel-rt (RHSA-2024:0439)
- 242847 Red Hat Update for kernel-rt (RHSA-2024:0431)
- 356571 Amazon Linux Security Advisory for kernel-livepatch : ALAS2LIVEPATCH-2023-155
- 6000220 Debian Security Update for linux (DSA 5492-1)
- 6120009 Google COS Security Update for sys-kernel/lakitu-kernel-6_1 (CVE-2023-3777)
- 6140371 AWS Bottlerocket Security Update for kernel (GHSA-7mhm-4p54-xrvq)
- 673595 EulerOS Security Update for kernel (EulerOS-SA-2023-3247)
- 673692 EulerOS Security Update for kernel (EulerOS-SA-2023-3275)
- 755238 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4378-1)
- 755240 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4375-1)
- 755249 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4414-1)
- 755397 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 7 for SLE 15 SP5) (SUSE-SU-2023:4781-1)
- 755398 SUSE Enterprise Linux Security Update for the Linux Kernel RT (Live Patch 6 for SLE 15 SP5) (SUSE-SU-2023:4776-1)
- 755422 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 37 for SLE 15 SP3) (SUSE-SU-2023:4839-1)
- 755465 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 6 for SLE 15 SP5) (SUSE-SU-2023:4867-1)
- 755563 SUSE Security Update for the linux kernel (SUSE-SU-2023:4351-1)
- 755564 SUSE Security Update for the linux kernel (SUSE-SU-2023:4348-1)
- 755566 SUSE Security Update for the linux kernel (SUSE-SU-2023:4345-1)