AZL-30057
Dashboard / Vulnerabilities / AZL-30057
Summary: CVE-2023-5197 affecting package kernel for versions less than 5.15.135.1-2
Details: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free. We recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-5197
Affected packages
Package
Name: kernel
Purl: pkg:rpm/azure-linux/kernel
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -5.15.135.1-2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
