CVE-2023-6817

HIGH

Linux Kernel 5.6-5.10.204 and 6.0-6.7 - Use-After-Free in nf_tables PIPAPO Set Walk

Title source: llm
STIX 2.1

Description

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_pipapo_walk did not skip inactive elements during set walk which could lead double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free. We recommend upgrading past commit 317eb9685095678f2c9f5a8189de698c5354316a.

Scores

CVSS v3 7.8
EPSS 0.0033
EPSS Percentile 25.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (3)
Linux/Kernel 5.6 - 6.7
linux/linux_kernel 6.7 rc1 (4 CPE variants)
linux/linux_kernel 5.6 - 5.10.204
Published Dec 18, 2023
Tracked Since Feb 18, 2026