QID 356920
Date Published: 2024-01-16
QID 356920: Amazon Linux Security Advisory for kernel-livepatch : ALAS2023LIVEPATCH-2023-020
A use-after-free vulnerability in the linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. the function nft_trans_gc_catchall did not remove the catchall set element from the catchall_list when the argument sync is true, making it possible to free a catchall set element many times. we recommend upgrading past commit 93995bf4af2c5a99e2a87f0cd5ce547d31eb7630. (
( CVE-2023-6111)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2023LIVEPATCH-2023-020 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2023LIVEPATCH-2023-020 -
alas.aws.amazon.com/AL2023/ALASLIVEPATCH-2023-020.html
CVEs related to QID 356920
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023LIVEPATCH-2023-020 | amazon linux 2023 |
|