A vulnerability in the Linux kernel allows for local exploitation through nftables.

A vulnerability has been discovered in the Netfilter subsystem (CVE-2023-6817), which, in theory, can be exploited by a local user to escalate their privileges in the system. The root of the problem lies in the use of freed memory (use-after-free) in the nf_tables module, which is responsible for the functionality of the nftables packet filter.

The vulnerability is relevant since Linux kernel version 5.6. The fix offered is in the test release of Linux kernel 6.7-rc5 and has been incorporated into the current stable branches 5.10.204, 5.15.143, 6.1.68, and 6.6.7.

The issue is caused by an error in the nft_pipapo_walk function, which does not check for duplicates when iterating over PIPAPO (Pile Packet Policies) elements. This leads to double freeing of memory. Successful attack requires access to nftables, which can be obtained by having CAP_NET_ADMIN rights in any user namespace or network namespace. These rights can be provided, for example, in isolated containers. To check your systems has been published a proof of concept exploit.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster