CVE-2023-32233
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Linuxmint, Linux Kernel, Red Hat, Red Os
- Linux Linux Kernel
- < 4.14.315, 4.19.283, 5.4.243, 5.10.180, 5.15.111, 6.1.28, 6.2.15, 6.3.2
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 13.0% (96th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2023-05-08
CVE-2023-32233 at NVD
8 known exploits for CVE-2023-32233
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Use After Free in Linux Linux_Kernel
Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation
Linux nf_tables 6.19.3 - Local Privilege Escalation
Exploit for OS Command Injection in Docker
Exploit for Use After Free in Linux Linux_Kernel
Exploit for Use After Free in Linux Linux_Kernel
Exploit for Use After Free in Linux Linux_Kernel
Exploit for Use After Free in Linux Linux_Kernel