CVE-2023-39192: Linux Kernel Netfilter Xtables Out-Of-Bounds Read Information Disclosure Vulnerability
A flaw was found in the Netfilter subsystem in the Linux kernel. The xtu32 module did not validate the fields in the xtu32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by setting the size fields with a value beyond the array boundaries, leading to a crash or information disclosure.
Other sources
An out-of-bounds read issue was found in the Linux kernel in the u32matchit() function, which is used to match packet content under netfilter. This flaw requires CAPNETADMIN to be exploited and could lead to information disclosure.
— Red Hat
Linux Kernel could allow a local authenticated attacker to obtain sensitive information, caused by an out-of-bounds read flaw in the u32matchit function in Netfilter Xtables. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
— IBM
This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the u32matchit function. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the kernel.
— ZDI
Affected Software
Remediation
Patch Available
Mitigation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-39192.
What is the title of this vulnerability?
The title of this vulnerability is Linux Kernel Netfilter Xtables Out-Of-Bounds Read Information Disclosure Vulnerability.
What is the severity of CVE-2023-39192?
The severity of CVE-2023-39192 is medium.
How can an attacker exploit this vulnerability?
An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
What is the affected software?
The affected software includes Linux Kernel versions up to 6.6, Redhat Enterprise Linux version 8.0, and Fedoraproject Fedora version 38.