UBUNTU-CVE-2023-3390
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-3390
UBUNTU-CVE-2023-3390
Summary:
Details: A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97
References: https://ubuntu.com/security/CVE-2023-3390, https://git.kernel.org/linus/1240eb93f0616b21c675416516ff3d74798fdc97, https://kernel.dance/#1240eb93f0616b21c675416516ff3d74798fdc97, https://ubuntu.com/security/notices/USN-6246-1, https://ubuntu.com/security/notices/USN-6250-1, https://ubuntu.com/security/notices/USN-6251-1, https://ubuntu.com/security/notices/USN-6252-1, https://ubuntu.com/security/notices/USN-6254-1, https://ubuntu.com/security/notices/USN-6255-1, https://ubuntu.com/security/notices/USN-6260-1, https://ubuntu.com/security/notices/USN-6261-1, https://ubuntu.com/security/notices/USN-6285-1, https://ubuntu.com/security/notices/USN-6385-1, https://www.cve.org/CVERecord?id=CVE-2023-3390
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
