CVE-2023-52433
Last modified
CVE-2023-52433 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this transaction might expired before such transaction ends. Skip sync GC for such elements otherwise commit path might walk over an already released object. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this transaction might expired before such transaction ends. Skip sync GC for such elements otherwise commit path might walk over an already released object. Once transaction is finished, async GC will collect such expired element.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Ontap Tools | 9 |
| Netapp | Ontap Tools | 10 |
| Linux | Linux Kernel | >= 6.5, < 6.5.4 |
References
- https://security.netapp.com/advisory/ntap-20240828-0003/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-52433?
How severe is CVE-2023-52433?
How do I fix CVE-2023-52433?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-52428In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can…7.5
- CVE-2023-52429dm_table_create in drivers/md/dm-table.c in the Linux kernel…5.5
- CVE-2023-5243The Login Screen Manager WordPress plugin through 3.5.2 does…4.8
- CVE-2023-52430The caddy-security plugin 1.1.20 for Caddy allows reflected …6.1
- CVE-2023-52431The Plack::Middleware::XSRFBlock package before 0.0.19 for P…8.8
- CVE-2023-52432Improper input validation in IpcTxSndSetLoopbackCtrl in libs…7.1
- CVE-2023-52434In the Linux kernel, the following vulnerability has been re…8
- CVE-2023-52435In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2023-52436In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-52437Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-52438In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-52439In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2023-52433?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
