Database/Kernel, userspace & hypervisor
Linux kernel (nf_tables): Use-after-free in nf_tables anonymous-set batch processing
Impact
Use-after-free in nf_tables anonymous-set batch processing - unprivileged local user to root, public exploit
Who can reach it
Any tenant process in a container with CAP_NET_ADMIN in a userns
What to do
Livepatchable; otherwise drain + reboot. Disable unprivileged user namespaces to blunt it
Fleet impact
How widespread
Universal - nf_tables is enabled by default in most distributions and every kernel through 6.3.1 is affected
Cost to remediate
node-reboot - kernel upgrade to 6.3.2+; mitigation is blocking CAP_NET_ADMIN/user namespaces, which many tenant workloads legitimately need
Why it hits the whole fleet
Use-after-free in nf_tables batch processing gives arbitrary kernel read/write and root from an unprivileged local user - in a container with a user namespace this is a straight escape to the GPU host
References
Related entries
- Linux kernel (nf_tables): UAF in nft_set_lookup_global after mixed named/anonymous set batches - local rootCVE-2023-3390 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): Stack out-of-bounds read/write in nft_byteorder_eval() - local root (Pwn2Own)CVE-2023-35001 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): UAF adding a rule with NFTA_RULE_CHAIN_ID - local rootCVE-2023-4147 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): Use-after-free in nft_verdict_init() - double-free to local rootCVE-2024-1086 · Linux kernel (nf_tables)High
- Linux kernel (nf_tables): Cross-table use-after-free in nf_tables leading to local privilege escalationCVE-2022-2586 · Linux kernel (nf_tables)Medium
- Linux kernel (nf_tables): Heap overflow in nft_set_elem_init() - local root, weaponised inside containersCVE-2022-34918 · Linux kernel (nf_tables)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.