Database/Kernel, userspace & hypervisor
Linux kernel (netfilter pipapo): Inactive elements mishandled in nft_pipapo_walk - use-after-free, local root
CVSS 7.8CVE-2023-6817Kernel, userspace & hypervisorcurated
Impact
Inactive elements mishandled in nft_pipapo_walk - use-after-free, local root
Who can reach it
Any tenant process in a container with CAP_NET_ADMIN in a userns
What to do
Livepatchable; otherwise drain + reboot
References
Related entries
- Linux kernel (netfilter pipapo): UAF from improper element removal in nft_pipapo_remove() - local rootCVE-2023-4004 · Linux kernel (netfilter pipapo)High
- Linux kernel (io_uring): Page use-after-free via io_uring buffer-ring mmap - unprivileged local user to rootCVE-2024-0582 · Linux kernel (io_uring)High
- Linux kernel (nf_tables): Use-after-free in nft_verdict_init() - double-free to local rootCVE-2024-1086 · Linux kernel (nf_tables)High
- Linux kernel (ksmbd): Use-after-free in ksmbd_tcp_new_connection() - in-kernel SMB serverCVE-2024-26592 · Linux kernel (ksmbd)High
- Linux kernel (drivers/iommu/iommufd): On a partially-failed access attach, iommufd overwrites the xarray id that tracksCVE-2024-26786 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/vfio/pci): A tenant races a DisINTx write to emulated config space against a SET_IRQS ioctl, soCVE-2024-26810 · Linux kernel (drivers/vfio/pci)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.