Back

MEDIUM

Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c

Published Aug 28, 2023

Description

A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.

Affected products

Remediation

Vendor solution

Mitigation for this issue is to skip loading the affected module "nftables" onto the system until we have a fix available. This can be done by a blacklist mechanism that will ensure the driver is not loaded at boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~

Red Hat statement

After engineering's review, it has been concluded that, this CVE do not impact any shipped RHEL Kernel.

Red Hat mitigation

Mitigation for this issue is to skip loading the affected module "nftables" onto the system until we have a fix available. This can be done by a blacklist mechanism that will ensure the driver is not loaded at boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 28, 2023
Updated Feb 27, 2025
Reserved Aug 28, 2023
CISA Vulnrichment
Updated Feb 26, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 12, 2023
ENISA EUVD
Assigner redhat
Published Aug 28, 2023
Updated Feb 27, 2025
Exploited since n/a
EUVD-2023-54424