SB2024051334 - Local denial of service in Linux kernel netfilter
Published: May 13, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2023-52581)
The vulnerability allows a local user to perform DoS attack on the target system.
The vulnerability exists due memory leak within the nft_trans_gc_space() function in net/netfilter/nf_tables_api.c. A local user can force the system to leak memory and perform denial of service attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4aea243b6853d06c1d160a9955b759189aa02b14
- https://git.kernel.org/stable/c/cf5000a7787cbc10341091d37245a42c119d26c5
- https://git.kernel.org/stable/c/a995a68e8a3b48533e47c856865d109a1f1a9d01
- https://git.kernel.org/stable/c/09c85f2d21ab6b5acba31a037985b13e8e6565b8
- https://git.kernel.org/stable/c/ef99506eaf1dc31feff1adfcfd68bc5535a22171
- https://git.kernel.org/stable/c/7e5d732e6902eb6a37b35480796838a145ae5f07
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.56