SB2024050861 - Local denial of service in Linux kernel netfilter
Published: May 8, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2023-52620)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions within the nf_tables_newset() function in net/netfilter/nf_tables_api.c when setting timeouts from userspace. A local user can bypass implemented security restrictions and perform a denial of service attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00b19ee0dcc1aef06294471ab489bae26d94524e
- https://git.kernel.org/stable/c/b7be6c737a179a76901c872f6b4c1d00552d9a1b
- https://git.kernel.org/stable/c/e26d3009efda338f19016df4175f354a9bd0a4ab
- https://git.kernel.org/stable/c/116b0e8e4673a5faa8a739a19b467010c4d3058c
- https://git.kernel.org/stable/c/49ce99ae43314d887153e07cec8bb6a647a19268
- https://git.kernel.org/stable/c/6f3ae02bbb62f151b19162d5fdc9fe3d48450323
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.215