NA

CVE-2023-4563

Published: 14/09/2023 Updated: 07/11/2023

Vulnerability Summary

Description<!---->A use-after-free flaw was found in the nftables sub-component due to a race problem between the set GC and transaction in the Linux Kernel. This flaw allows a local malicious user to crash the system due to a missing call to `nft_set_elem_mark_busy`, causing double deactivation of the element and possibly leading to a kernel information leak problem.A use-after-free flaw was found in the nftables sub-component due to a race problem between the set GC and transaction in the Linux Kernel. This flaw allows a local malicious user to crash the system due to a missing call to nft_set_elem_mark_busy, causing double deactivation of the element and possibly leading to a kernel information leak problem.

Vendor Advisories

Description<!---->A use-after-free flaw was found in the nftables sub-component due to a race problem between the set GC and transaction in the Linux Kernel This flaw allows a local attacker to crash the system due to a missing call to `nft_set_elem_mark_busy`, causing double deactivation of the element and possibly leading to a kernel information ...

Github Repositories

A quilt-like series of patches plus scripts and .spec files to produce the kernel RPM package. If you are looking for a ready-to-use kernel tree, have a look at https://github.com/openSUSE/kernel

SUSE Kernel Repository Overview The kernel-source repository contains sources, configuration files, package definitions and supporting scripts for the SUSE kernels The SUSE kernels are generated from the upstream Linux kernel sources found at kernelorg/, on top of which a number of patches are applied The expanded kernel source tree is configured and built, resulting

SUSE Kernel Patches

SUSE Kernel Repository Overview The kernel-source repository contains sources, configuration files, package definitions and supporting scripts for the SUSE kernels The SUSE kernels are generated from the upstream Linux kernel sources found at kernelorg/, on top of which a number of patches are applied The expanded kernel source tree is configured and built, resulting