CVE-2023-3777

Updated: 2023-09-06

CWE: CWE-416 Use After Free

Description:

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances. We recommend upgrading past commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8.

CVSS3: 7.8


Vendor State

OS Vendor version Errata
Ubuntu 22.04 Azure 5.15.0-1045.52 USN-6332-1
Ubuntu 20.04 HWE AWS 5.15.0-1043.48~20.04.1 USN-6315-1
Ubuntu 22.04 5.15.0-82.91 USN-6315-1
Ubuntu 22.04 AWS 5.15.0-1043.48 USN-6315-1
Debian 11 5.10.191-1 DSA-5480-1
Debian 12 6.1.52-1 DSA-5492-1
Amazon Linux 2 5.10 5.10.192-182.736.amzn2 ALASKERNEL-5.10-2023-039

KernelCare State

OS Original kernel version State
Ubuntu 22.04 Azure
Planned
Ubuntu 20.04 HWE AWS
Planned
Ubuntu 22.04
Planned
Ubuntu 22.04 AWS
Planned
Debian 11
Will Not Fix
Debian 12
Planned
Amazon Linux 2 5.10
Planned