A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free.
We recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-5197.json"
[
{
"digest": {
"line_hashes": [
"162872388343165377482052664487884534481",
"22907386926899104592626891372617324838",
"10294391177194120625629407289240414714",
"191553781029270481326199172408108785358",
"277884414740493960964817915768796707450",
"22907386926899104592626891372617324838",
"10294391177194120625629407289240414714",
"215789687288443202133092521185729411725",
"287047632816825789469012620969310482005",
"206742536767080275468521971333270626430",
"63971813748120108119565232978349215337",
"112211173989860960111867274523083971279",
"42148371776399833053319363979829181266",
"20359868716618856941825007062695829046",
"291595599330532127739422607485466614479",
"279253083450191104728079042717821539793",
"63270132509948475704778622850198058419",
"213339940337085552108717257561394970201",
"44356258499096289972019246019407071252",
"328259759014001583542959010049774989655",
"25419272036556182902012665248802695353",
"73435355377901363416267584639284449125",
"274182681515475864348494481461744114790",
"49363457601412616259603092635912234254",
"216003874697303190761144321955598907495",
"53053654495126990883926356104076990684",
"111896131861200010721819399256497533670"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "net/netfilter/nf_tables_api.c"
},
"signature_type": "Line",
"id": "CVE-2023-5197-4381223f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@f15f29fd4779be8a418b66e9d52979bb6d6c2325",
"deprecated": false
}
]