Executive brief
A security vulnerability has been identified in the Linux kernel's networking subsystem (Netfilter), which is responsible for filtering and managing network traffic. A local user with specific network administration permissions can exploit this flaw to gain full administrative control (root privileges) over the system. This could lead to unauthorized access to sensitive data, system instability, or a complete takeover of the affected machine.
Technical details
A use-after-free vulnerability exists in the Linux kernel's nf_tables component within the PIPAPO (Pile Packet Policies) set implementation. The root cause is located in the 'nft_pipapo_walk' function, which fails to skip inactive elements during a set walk. This allows a local attacker with CAP_NET_ADMIN privileges to trigger a double deactivation of elements by sending the NFT_MSG_DELSETELEM command twice in a single transaction, leading to a use-after-free condition. Successful exploitation can result in local privilege escalation or a denial of service (system crash). The issue was introduced in version 5.6 and is fixed in stable releases 5.10.204, 5.15.143, 6.1.68, 6.6.7, and mainline 6.7-rc5.
Affected products
- Linux Linux Kernel 5.6 to 6.6.7, 6.7-rc1 to 6.7-rc4
Timeline
- 2023-12-01: patched: Initial patch authored by Florian Westphal
- 2023-12-18: disclosed: CVE-2023-6817 published
- 2023-12-22: advisory: Detailed technical disclosure on oss-security mailing list
References
- http://packetstormsecurity.com/files/177029/Kernel-Live-Patch-Security-Notice-LSN-0100-1.html
- http://www.openwall.com/lists/oss-security/2023/12/22/13
- http://www.openwall.com/lists/oss-security/2023/12/22/6
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=317eb9685095678f2c9f5a8189de698c5354316a
- https://kernel.dance/317eb9685095678f2c9f5a8189de698c5354316a
- https://lists.debian.org/debian-lts-announce/2024/01/msg00005.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html