Kernel: refcount leak in ctnetlink_create_conntrack()
Published Jan 2, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.30%
Description
A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | affected | |
| Red Hat | Red Hat Enterprise Linux 9 | affected |
Configuration 1
- < 6.3
Configuration 2
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.133.1.el8_2
Fixed · RHSA-2024:2006
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-0:4.18.0-193.133.1.el8_2
Fixed · RHSA-2024:2006
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-rt-0:4.18.0-193.133.1.rt13.184.el8_2
Fixed · RHSA-2024:2008
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kernel-0:4.18.0-193.133.1.el8_2
Fixed · RHSA-2024:2006
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.125.1.el8_4
Fixed · RHSA-2024:1367
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-0:4.18.0-305.125.1.el8_4
Fixed · RHSA-2024:1367
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
kernel-rt-0:4.18.0-305.125.1.rt7.201.el8_4
Fixed · RHSA-2024:1382
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
kernel-0:4.18.0-305.125.1.el8_4
Fixed · RHSA-2024:1367
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.95.1.el8_6
Fixed · RHSA-2024:1188
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.51.1.el8_8
Fixed · RHSA-2024:1404
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.93.2.el9_0
Fixed · RHSA-2024:1250
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.93.1.rt21.165.el9_0
Fixed · RHSA-2024:1306
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.52.1.el9_2
Fixed · RHSA-2024:0723
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.52.1.rt14.337.el9_2
Fixed · RHSA-2024:0725
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.95.1.el8_6
Fixed · RHSA-2024:1188
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.133.1.el8_2 | Fixed | RHSA-2024:2006 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-0:4.18.0-193.133.1.el8_2 | Fixed | RHSA-2024:2006 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-rt-0:4.18.0-193.133.1.rt13.184.el8_2 | Fixed | RHSA-2024:2008 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kernel-0:4.18.0-193.133.1.el8_2 | Fixed | RHSA-2024:2006 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.125.1.el8_4 | Fixed | RHSA-2024:1367 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-0:4.18.0-305.125.1.el8_4 | Fixed | RHSA-2024:1367 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | kernel-rt-0:4.18.0-305.125.1.rt7.201.el8_4 | Fixed | RHSA-2024:1382 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | kernel-0:4.18.0-305.125.1.el8_4 | Fixed | RHSA-2024:1367 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.95.1.el8_6 | Fixed | RHSA-2024:1188 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.51.1.el8_8 | Fixed | RHSA-2024:1404 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.93.2.el9_0 | Fixed | RHSA-2024:1250 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.93.1.rt21.165.el9_0 | Fixed | RHSA-2024:1306 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.52.1.el9_2 | Fixed | RHSA-2024:0723 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.52.1.rt14.337.el9_2 | Fixed | RHSA-2024:0725 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.95.1.el8_6 | Fixed | RHSA-2024:1188 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Triggering this issue requires the ability to create user/net namespaces.
On non-containerized deployments of Red Hat Enterprise Linux 8, you can disable user namespaces by setting user.max_user_namespaces to 0:
# echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf
On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled.
Alternatively, skip loading the affected netfilter module (i.e., nf_conntrack_netlink) onto the system until we have a fix available. This can be done by a blacklist mechanism which will ensure the driver is not loaded at boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~
Red Hat mitigation
Triggering this issue requires the ability to create user/net namespaces. On non-containerized deployments of Red Hat Enterprise Linux 8, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled. Alternatively, skip loading the affected netfilter module (i.e., nf_conntrack_netlink) onto the system until we have a fix available. This can be done by a blacklist mechanism which will ensure the driver is not loaded at boot time. ~~~ How do I blacklist a kernel module to prevent it from loading automatically? https://access.redhat.com/solutions/41278 ~~~
References (16)
- https://access.redhat.com/errata/RHSA-2024:0723 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0725 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1188 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1250 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1306 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1367 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1382 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:1404 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2006 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2008 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-7192 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2256279 issue-trackingx_refsource_REDHATIssue TrackingPatch
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59373 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=ac4893980bbe79ce383daf9a0885666a30fe4c83 Mailing ListPatch
- https://nvd.nist.gov/vuln/detail/CVE-2023-7192
- https://www.cve.org/CVERecord?id=CVE-2023-7192
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data