packetstormsecurity.com
http://packetstormsecurity.com/files/177029/Kernel-Live-Patch-Security-Notice-LSN-0100-1.html CVE-2023-6817
HIGH
Use-after-free in Linux kernel's netfilter: nf_tables component
Record summary
CVE-2023-6817 has a selected CVSS score of 7.8 (high).
Description
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_pipapo_walk did not skip inactive elements during set walk which could lead double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free. We recommend upgrading past commit 317eb9685095678f2c9f5a8189de698c5354316a.
Description source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
KernelBrowse Linux / KernelDefault status: unaffected | CVE List | 5.6 to < 6.7 | affected |
SIMATIC S7-1500 CPU 1518-4 PN/DP MFPBrowse Siemens / SIMATIC S7-1500 CPU 1518-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.0 to < V3.1.5 | affected |
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPBrowse Siemens / SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.0 to < V3.1.5 | affected |
SIMATIC S7-1500 TM MFP - GNU/Linux subsystemBrowse Siemens / SIMATIC S7-1500 TM MFP - GNU/Linux subsystemDefault status: unknown | CVE List | Before * | affected |
SIPLUS S7-1500 CPU 1518-4 PN/DP MFPBrowse Siemens / SIPLUS S7-1500 CPU 1518-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.0 to < V3.1.5 | affected |
References
9openwall.com
http://www.openwall.com/lists/oss-security/2023/12/22/13 openwall.com
http://www.openwall.com/lists/oss-security/2023/12/22/6 cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-265688.html cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-398330.html git.kernel.orgpatch
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=317eb9685095678f2c9f5a8189de698c5354316a kernel.dance
https://kernel.dance/317eb9685095678f2c9f5a8189de698c5354316a lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/01/msg00005.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-6817