CVE-2023-54035
Last modified
CVE-2023-54035 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix underflow in chain reference counter Set element addition error path decrements reference counter on chains twice: once on element release and again via nft_data_release(). Then, d6b478666ffa ("netfilter: nf_tables: fix underflow in object reference counter") incorrectly fixed this by removing the stateful object reference count decrement. Restore the stateful object decrement as in b91d90368837 ("netfilter: nf_tables: fix leaking object reference count") and let nft_data_release() decrement the chain reference counter, so this is done only once.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix underflow in chain reference counter Set element addition error path decrements reference counter on chains twice: once on element release and again via nft_data_release(). Then, d6b478666ffa ("netfilter: nf_tables: fix underflow in object reference counter") incorrectly fixed this by removing the stateful object reference count decrement. Restore the stateful object decrement as in b91d90368837 ("netfilter: nf_tables: fix leaking object reference count") and let nft_data_release() decrement the chain reference counter, so this is done only once.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 35651fde1a7bb54dde0a46d35cd0d7136869ae86, < b068314fd8ce751a7f906e55bb90f3551815f1a0; >= 628bd3e49cba1c066228e23d71a852c23e26da73, < 9c959671abc7d4ffdf34eed10c64492d43cb6a3c; >= 628bd3e49cba1c066228e23d71a852c23e26da73, < b389139f12f287b8ed2e2628b72df89a081f0b59; bc9f791d2593f17e39f87c6e2b3a36549a3705b1; 3c7ec098e3b588434a8b07ea9b5b36f04cef1f50; a136b7942ad2a50de708f76ea299ccb45ac7a7f9; 25aa2ad37c2162be1c0bc4fe6397f7e4c13f00f8; d60be2da67d172aecf866302c91ea11533eca4d9; dc7cdf8cbcbf8b13de1df93f356ec04cdeef5c41; >= 4.19.316, < 4.20; >= 5.4.262, < 5.5; >= 5.10.188, < 5.11; >= 5.15.121, < 5.16; >= 6.3.10, < 6.4 |
| Linux | Linux | 6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-54035?
How severe is CVE-2023-54035?
How do I fix CVE-2023-54035?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-5403Server hostname translation to IP address manipulation which…8.1
- CVE-2023-54030In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54031In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54032In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54033In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54034In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54036In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54037In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54038In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54039In the Linux kernel, the following vulnerability has been re…
- CVE-2023-5404Server receiving a malformed message can cause a pointer to …8.1
- CVE-2023-54040In the Linux kernel, the following vulnerability has been re…8.8
Are you affected by CVE-2023-54035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
