CVE-2023-54243

Linux Kernel Use-After-Free in ebtables Table Blob Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix table blob use-after-free We are not allowed to return an error at this point. Looking at the code it looks like ret is always 0 at this point, but its not. t = find_table_lock(net, repl->name, &ret, &ebt_mutex); ... this can return a valid table, with ret != 0. This bug causes update of table->private with the new blob, but then frees the blob right away in the caller. Syzbot report: BUG: KASAN: vmalloc-out-of-bounds in __ebt_unregister_table+0xc00/0xcd0 net/bridge/netfilter/ebtables.c:1168 Read of size 4 at addr ffffc90005425000 by task kworker/u4:4/74 Workqueue: netns cleanup_net Call Trace: kasan_report+0xbf/0x1f0 mm/kasan/report.c:517 __ebt_unregister_table+0xc00/0xcd0 net/bridge/netfilter/ebtables.c:1168 ebt_unregister_table+0x35/0x40 net/bridge/netfilter/ebtables.c:1372 ops_exit_list+0xb0/0x170 net/core/net_namespace.c:169 cleanup_net+0x4ee/0xb10 net/core/net_namespace.c:613 ... ip(6)tables appears to be ok (ret should be 0 at this point) but make this more obvious.

Scores

EPSS 0.0017
EPSS Percentile 7.2%

Details

Status published
Products (26)
linux/Kernel 3.15.0 - 5.10.173linux
linux/Kernel 5.11.0 - 5.15.100linux
linux/Kernel 5.16.0 - 6.1.18linux
linux/Kernel 6.2.0 - 6.2.5linux
Linux/Linux < 3.15
Linux/Linux 3.10.41 - 3.11
Linux/Linux 3.12.21 - 3.13
Linux/Linux 3.14.5 - 3.15
Linux/Linux 3.15
Linux/Linux 3.2.60 - 3.3
... and 16 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026