CVE-2023-54035

HIGHCVSS 7.8/10EPSS 0.16%

Last modified

CVE-2023-54035 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix underflow in chain reference counter Set element addition error path decrements reference counter on chains twice: once on element release and again via nft_data_release(). Then, d6b478666ffa ("netfilter: nf_tables: fix underflow in object reference counter") incorrectly fixed this by removing the stateful object reference count decrement. Restore the stateful object decrement as in b91d90368837 ("netfilter: nf_tables: fix leaking object reference count") and let nft_data_release() decrement the chain reference counter, so this is done only once.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix underflow in chain reference counter Set element addition error path decrements reference counter on chains twice: once on element release and again via nft_data_release(). Then, d6b478666ffa ("netfilter: nf_tables: fix underflow in object reference counter") incorrectly fixed this by removing the stateful object reference count decrement. Restore the stateful object decrement as in b91d90368837 ("netfilter: nf_tables: fix leaking object reference count") and let nft_data_release() decrement the chain reference counter, so this is done only once.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.16%

5.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 35651fde1a7bb54dde0a46d35cd0d7136869ae86, < b068314fd8ce751a7f906e55bb90f3551815f1a0; >= 628bd3e49cba1c066228e23d71a852c23e26da73, < 9c959671abc7d4ffdf34eed10c64492d43cb6a3c; >= 628bd3e49cba1c066228e23d71a852c23e26da73, < b389139f12f287b8ed2e2628b72df89a081f0b59; bc9f791d2593f17e39f87c6e2b3a36549a3705b1; 3c7ec098e3b588434a8b07ea9b5b36f04cef1f50; a136b7942ad2a50de708f76ea299ccb45ac7a7f9; 25aa2ad37c2162be1c0bc4fe6397f7e4c13f00f8; d60be2da67d172aecf866302c91ea11533eca4d9; dc7cdf8cbcbf8b13de1df93f356ec04cdeef5c41; >= 4.19.316, < 4.20; >= 5.4.262, < 5.5; >= 5.10.188, < 5.11; >= 5.15.121, < 5.16; >= 6.3.10, < 6.4
LinuxLinux6.4

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2023-54035?
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix underflow in chain reference counter Set element addition error path decrements reference counter on chains twice: once on element release and again via nft_data_release(). Then, d6b478666ffa ("netfilter: nf_tables: fix underflow in object reference counter") incorrectly fixed this by removing the stateful object reference count decrement. Restore the stateful object decrement as in b91d90368837 ("netfilter: nf_tables: fix leaking object reference count") and let nft_data_release() decrement the chain reference counter, so this is done only once.
How severe is CVE-2023-54035?
CVE-2023-54035 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2023-54035?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-54035?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST