CVE detail
CVE-2023-3390
A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 17.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- https://www.debian.org/security/2023/dsa-5461www.debian.org
No excerpt available.
Vendor Advisorywww.debian.orgJun 28, 2023, 9:15 PM - https://www.debian.org/security/2023/dsa-5448www.debian.org
No excerpt available.
Vendor Advisorywww.debian.orgJun 28, 2023, 9:15 PM - http://packetstormsecurity.com/files/174577/Kernel-Live-Patch-Security-Notice-LSN-0097-1.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comJun 28, 2023, 9:15 PM - https://security.netapp.com/advisory/ntap-20230818-0004/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comJun 28, 2023, 9:15 PM No excerpt available.
Exploitpacketstorm.newsJun 28, 2023, 9:15 PMNo excerpt available.
Vendor Advisorylists.debian.orgJun 28, 2023, 9:15 PMNo excerpt available.
Vendor Advisorylists.debian.orgJun 28, 2023, 9:15 PMNo excerpt available.
Vendor Advisorylists.debian.orgJun 28, 2023, 9:15 PMNo excerpt available.
Vendor Advisorylists.debian.orgJun 28, 2023, 9:15 PMNo excerpt available.
Vendor Advisorykernel.danceJun 28, 2023, 9:15 PM- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=1240eb93f0616b21c675416516ff3d74798fdc97git.kernel.org
No excerpt available.
Vendor Advisorygit.kernel.orgJun 28, 2023, 9:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-35828CVSS 7.0 · High
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.
- CVE-2023-35826CVSS 7.0 · High
An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.
- CVE-2023-3111CVSS 7.8 · High
A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_b…
- CVE-2023-1989CVSS 7.0 · High
A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race…
- CVE-2023-1838CVSS 7.1 · High
A use-after-free flaw was found in vhost_net_set_backend in drivers/vhost/net.c in virtio network subcomponent in the Linux kernel due to a double fget. This flaw could allow a lo…
- CVE-2022-45919CVSS 7.0 · High
An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free can occur is there is a disconnect after an open, because…