CVE-2023-32233

Updated: 2026-02-27 02:58:58.56896

Description:

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Released 2024-01-19 10:09:40
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2023-06-15 09:07:46 Not affected: CVE-2023-32233 targets the Netfilter nf_tables subsystem’s handling of anonymous set...
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Already Fixed 2023-11-15 10:11:06
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2023:1690287378 2023-07-25 09:10:45
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2023:1690294029 2023-07-25 11:06:36
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2023-06-15 09:07:46
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2023-06-15 09:07:46 Not affected: CVE-2023-32233 targets the Netfilter nf_tables subsystem’s handling of anonymous set...
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Released CLSA-2023:1685972472 2023-06-05 11:04:49
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2023:1688072342 2023-06-29 17:05:22
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Released 2023-08-31 03:18:53