Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c
Published Aug 28, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.26%
Description
A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.
Affected products
No data.
Configuration 1
- < 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
- 6.5
Configuration 2
- 8.0
- 9.0
Configuration 3
- 12.0
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is to skip loading the affected module "nftables" onto the system until we have a fix available. This can be done by a blacklist mechanism that will ensure the driver is not loaded at boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~
Red Hat statement
After engineering's review, it has been concluded that, this CVE do not impact any shipped RHEL Kernel.
Red Hat mitigation
Mitigation for this issue is to skip loading the affected module "nftables" onto the system until we have a fix available. This can be done by a blacklist mechanism that will ensure the driver is not loaded at boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~
References (7)
- https://access.redhat.com/security/cve/CVE-2023-4569 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2235470 issue-trackingx_refsource_REDHATIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54424 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-4569
- https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230812110526.49808-1-fw@strlen.de/ Mailing ListPatch
- https://www.cve.org/CVERecord?id=CVE-2023-4569
- https://www.debian.org/security/2023/dsa-5492 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-4569 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2235470 | issue-trackingx_refsource_REDHATIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54424 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-4569 | ||
| https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230812110526.49808-1-fw@strlen.de/ | Mailing ListPatch | |
| https://www.cve.org/CVERecord?id=CVE-2023-4569 | ||
| https://www.debian.org/security/2023/dsa-5492 | Third Party Advisory |
Change history (0)
No recorded changes yet.