ZeroHour

CVE-2023-32233

CVSS 3.1
7.8 high
EPSS
13%p96
Published
()
Modified
Description

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

Vendors
linuxredhatnetapp
Products
linux kernel, enterprise linux, hci baseboard management controller
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news