Use-after-free in Linux kernel's netfilter: nf_tables component
Summary
| CVE | CVE-2023-4244 |
|---|---|
| State | PUBLISHED |
| Assigner | |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-06 14:15:11 UTC |
| Updated | 2026-07-30 19:14:53 UTC |
| Description | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability. We recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8. |
Risk And Classification
Primary CVSS: v3.1 7 HIGH from [email protected]
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.002200000 probability, percentile 0.125830000 (date 2026-07-29)
Problem Types: CWE-416 | CWE-416 CWE-416 Use After Free
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Kernel | affected 0.0 4.19.316 custom | Not specified |
| CNA | Linux | Kernel | affected 4.20 5.4.262 custom | Not specified |
| CNA | Linux | Kernel | affected 5.5 5.10.198 custom | Not specified |
| CNA | Linux | Kernel | affected 5.11 5.15.134 custom | Not specified |
| CNA | Linux | Kernel | affected 5.16 6.1.56 custom | Not specified |
| CNA | Linux | Kernel | affected 6.2 6.4.11 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 3623-1] linux-5.10 security update | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Issue Tracking, Mailing List, Patch, Vendor Advisory |
| kernel.dance/3e91b0ebd994635df2346353322ac51ce84ce6d8 | af854a3a-2127-422b-91ae-364da2661108 | kernel.dance | Patch, Vendor Advisory |
| lists.debian.org/debian-lts-announce/2024/01/msg00004.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Bien Pham from Team Orca of Sea Security Team (en)
Legacy QID Mappings
- 161237 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-13043)
- 161344 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2024-12153)
- 161345 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2024-12154)
- 161347 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2024-12151)
- 161417 Oracle Enterprise Linux Security Update for kernel (ELSA-2024-1248)
- 199841 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6444-1)
- 199844 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6445-1)
- 199847 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6443-1)
- 199848 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6446-1)
- 199858 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6445-2)
- 199859 Ubuntu Security Notification for Linux kernel (StarFive) Vulnerabilities (USN-6444-2)
- 199861 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6446-2)
- 199868 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-6446-3)
- 199881 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6461-1)
- 199883 Ubuntu Security Notification for Linux kernel (NVIDIA) Vulnerabilities (USN-6466-1)
- 199938 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6503-1)
- 199982 Ubuntu Security Notification for Linux kernel (GCP) Vulnerability (USN-6537-1)
- 200171 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6681-1)
- 200183 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6681-2)
- 200192 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6681-3)
- 200203 Ubuntu Security Notification for Linux kernel (AWS) Vulnerabilities (USN-6681-4)
- 200221 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-6716-1)
- 242985 Red Hat Update for kernel (RHSA-2024:1018)
- 242986 Red Hat Update for kernel-rt (RHSA-2024:1019)
- 243052 Red Hat Update for kernel (RHSA-2024:1248)
- 356530 Amazon Linux Security Advisory for kernel : ALAS2023-2023-385
- 356569 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-028
- 356612 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2023-042
- 6000265 Debian Security Update for linux-5.10 (DLA 3623-1)
- 6000429 Debian Security Update for linux (DLA 3710-1)
- 6140275 AWS Bottlerocket Security Update for kernel (GHSA-rmmr-77h8-w26x)
- 6140298 AWS Bottlerocket Security Update for kernel (GHSA-gg8j-j5j9-mhrh)
- 673595 EulerOS Security Update for kernel (EulerOS-SA-2023-3247)
- 673692 EulerOS Security Update for kernel (EulerOS-SA-2023-3275)
- 907595 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (28676-1)