CVE-2023-52620: netfilter: nf_tables: disallow timeout for anonymous sets
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftables: disallow timeout for anonymous sets
Never used from userspace, disallow these parameters.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftables: disallow timeout for anonymous sets
The Linux kernel CVE team has assigned CVE-2023-52620 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024032147-CVE-2023-52620-11a9@gregkh/T
— Red Hat
Linux Kernel is vulnerable to a denial of service, caused by a resource injection flaw in timeout parameter in nftables. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52620?
CVE-2023-52620 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2023-52620?
To fix CVE-2023-52620, upgrade to kernel version 5.15.151, 6.1.81, or 6.4 for Red Hat systems, or to the latest patched version for Debian.
What type of vulnerability is CVE-2023-52620?
CVE-2023-52620 is a vulnerability related to the netfilter subsystem in the Linux kernel.
Which Linux kernel versions are affected by CVE-2023-52620?
Affected Linux kernel versions include versions before 5.15.151, 6.1.81, and 6.4 for Red Hat, along with certain versions listed for Debian.
Is CVE-2023-52620 exploitable remotely?
CVE-2023-52620 is not directly exploitable from userspace, thus posing less risk for remote exploitation.