CLSA-2023-1688072342

    Dashboard / Vulnerabilities / CLSA-2023-1688072342

    CLSA-2023-1688072342

    Published: 29 Jun 2023Last Modified: 4 Jun 2026

    Summary: Fix of 5 CVEs

    Details: * CVE-2023-32233 // CVE-url: https://ubuntu.com/security/CVE-2023-32233 - netfilter: nf_tables: add nft_set_is_anonymous() helper - netfilter: nf_tables: split set destruction in deactivate and destroy phase - netfilter: nf_tables: unbind set in rule from commit path - netfilter: nf_tables: fix set double-free in abort path - netfilter: nf_tables: bogus EBUSY when deleting set after flush - netfilter: nf_tables: use-after-free in failing rule with bound set - netfilter: nf_tables: deactivate anonymous set from preparation phase * Bionic update: upstream stable patchset 2018-12-12 (LP: #1808185) // CVE- url: https://ubuntu.com/security/CVE-2023-32233 - netfilter: nf_tables: bogus EBUSY in chain deletions * CVE-url: https://ubuntu.com/security/CVE-2023-32233 - netfilter: nf_tables: release objects on netns destruction - netfilter: nf_tables: destroy basechain and rules on netdevice removal - netfilter: nft_hash: support deletion of inactive elements - netfilter: nf_tables: remove check against removal of inactive objects - netfilter: nfnetlink: pass down netns pointer to call() and call_rcu() - netfilter: nf_tables: introduce nft_setelem_parse_flags() helper - netfilter: nft_rbtree: introduce nft_rbtree_interval_end() helper - netfilter: nft_rbtree: allow adjacent intervals with dynamic updates - netfilter: nf_tables: parse element flags from nft_del_setelem() - netfilter: nf_tables: reject loops from set element jump to chain - netfilter: nf_tables: fix wrong destroy anonymous sets if binding fails - netfilter: nf_tables: add generic macros to check for generation mask - netfilter: nf_tables: add generation mask to tables - netfilter: nf_tables: add generation mask to chains - netfilter: nf_tables: add generation mask to sets - netfilter: nf_tables: get rid of NFT_BASECHAIN_DISABLED - netlink: add NLM_F_NONREC flag for deletion requests - netfilter: nf_tables: add support for inverted logic in nft_lookup - netfilter: nf_tables: get rid of possible_net_t from set and basechain - netfilter: nf_tables: simplify the basic expressions' init routine - netfilter: nf_tables: fix *leak* when expr clone fail - netfilter: nf_tables: missing sanitization in data from userspace - netfilter: nf_tables: revisit chain/object refcounting from elements * CVE-2023-1380 // CVE-url: https://ubuntu.com/security/CVE-2023-1380 - wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() * CVE-url: https://ubuntu.com/security/CVE-2023-2124 - xfs: verify buffer contents when we skip log replay * Bionic update: upstream stable patchset 2023-04-05 (LP: #2015399) // CVE- url: https://ubuntu.com/security/CVE-2023-32269 - netrom: Fix use-after-free caused by accept on already connected socket * Bionic update: upstream stable patchset 2023-04-05 (LP: #2015399) // CVE- url: https://ubuntu.com/security/CVE-2023-2162 - scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress

    Affected packages

    Package

    Name: linux-buildinfo-4.4.0-241-tuxcare.els12-generic

    Purl: pkg:deb/tuxcare/linux-buildinfo-4.4.0-241-tuxcare.els12-generic?distro=ubuntu-16.04

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.4.0-241.275

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2023-1688072342 | CVE-DB