CVE-2023-4569

Updated: 2023-11-13

CWE: CWE-402: Transmission of Private Resources into a New Sphere ('Resource Leak')

Description:

A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.

CVSS3: 5.5


Vendor State

OS Vendor version Errata
Debian 12 6.1.52-1 DSA-5492-1
Ubuntu 20.04 HWE AWS 5.15.0-1045.50~20.04.1 USN-6386-1
Ubuntu 20.04 HWE Azure 5.15.0-1047.54~20.04.1 USN-6386-1
Ubuntu 22.04 AWS 5.15.0-1045.50 USN-6386-1
Ubuntu 22.04 Azure 5.15.0-1047.54 USN-6386-1
Ubuntu 22.04 5.15.0-84.93 USN-6386-1

KernelCare State

OS Original kernel version State
Debian 12
Planned
Ubuntu 20.04 HWE AWS
Planned
Ubuntu 20.04 HWE Azure
Planned
Ubuntu 22.04 AWS
Planned
Ubuntu 22.04 Azure
Planned
Ubuntu 22.04
Planned