Database/Kernel, userspace & hypervisor
Linux kernel (netfilter): Integer overflow in nft_payload_copy_vlan - stack leak plus local privilege escalation
CVSS 7.8CVE-2023-0179Kernel, userspace & hypervisorcurated
Impact
Integer overflow in nft_payload_copy_vlan - stack leak plus local privilege escalation
Who can reach it
Any tenant process in a container with CAP_NET_ADMIN in a userns
What to do
Livepatchable; otherwise drain + reboot
References
Related entries
- Linux kernel (netfilter): nft_chain_filter NETDEV_UNREGISTER mishandling for inet/ingress basechains - UAFCVE-2024-26808 · Linux kernel (netfilter)Medium
- Linux kernel (netfilter): Use-after-free write in the netfilter subsystem - privilege escalation to rootCVE-2022-32250 · Linux kernel (netfilter)High
- Linux kernel (ALSA): Use-after-free in snd_ctl_elem_read - local privilege escalationCVE-2023-0266 · Linux kernel (ALSA)High
- Oracle VirtualBox: Core component flaw allowing a low-privileged guest user to take over the host VirtualBoxCVE-2023-21987 · Oracle VirtualBoxHigh
- Linux kernel (io_uring): io_uring fixed-buffer registration gives out-of-bounds access to physical memoryCVE-2023-2598 · Linux kernel (io_uring)High
- Linux kernel (nf_tables): Use-after-free in nft_chain_lookup_byid() - local root (Pwn2Own Vancouver chain)CVE-2023-31248 · Linux kernel (nf_tables)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.