CVE-2023-4147: Fixes in Linux Kernel
A flaw in the Linux Kernel found. For the netfilter, nftablesnewrule when adding a rule with NFTARULECHAINID can lead to use-after-free.
Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0ebc1064e4874d5987722a2ddbc18f94aa53b211
Other sources
A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTARULECHAINID. This flaw allows a local user to crash or escalate their privileges on the system.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-4369
- CVE-2023-20593
- CVE-2023-4211
- CVE-2023-4128
- CVE-2023-3390
- CVE-2023-32804
- CVE-2022-40982
- CVE-2023-2312
- CVE-2023-4349
- CVE-2023-4350
- CVE-2023-4351
- CVE-2023-4352
- CVE-2023-4353
- CVE-2023-4354
- CVE-2023-4355
- CVE-2023-4356
- CVE-2023-4357
- CVE-2023-4358
- CVE-2023-4359
- CVE-2023-4360
- CVE-2023-4361
- CVE-2023-4362
- CVE-2023-4363
- CVE-2023-4364
- CVE-2023-4365
- CVE-2023-4366
- CVE-2023-4367
- CVE-2023-4368
- CVE-2023-21264
- CVE-2020-29374
Frequently Asked Questions
What is CVE-2023-4147?
CVE-2023-4147 is a use-after-free flaw found in the Linux kernel's Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID.
How does CVE-2023-4147 impact the system?
CVE-2023-4147 allows a local user to crash or escalate their privileges on the system.
What is the severity of CVE-2023-4147?
CVE-2023-4147 has a severity rating of 7.8 (High).
Which software are affected by CVE-2023-4147?
Linux kernel versions 6.5 and earlier, Fedora 38, and Redhat Enterprise Linux 9.0 are affected by CVE-2023-4147.
How do I fix CVE-2023-4147?
Apply the recommended patches and updates provided by the respective vendors to mitigate CVE-2023-4147.