Vulnerabilities in Netfilter and io_uring allow for privilege escalation in the system

Vulnerabilities have been discovered in the Linux kernel subsystems Netfilter and io_uring, allowing a local user to elevate their privileges in the system:

  • The vulnerability (CVE-2023-32233) in the Netfilter subsystem is caused by a use-after-free memory access in the nf_tables module, which facilitates the operation of the nftables packet filter. This vulnerability can be exploited by sending specially crafted requests to update the nftables configuration. To conduct an attack, access to nftables is required, which can be obtained in a separate network namespace with the rights of CLONE_NEWUSER, CLONE_NEWNS, or CLONE_NEWNET (for example, when able to run an isolated container).

    To give users time to install updates, the researcher who discovered the issue promised to postpone the publication of detailed information and a working exploit example providing root shell for a week (until May 15). The vulnerability has been fixed in the 6.4-rc1 update. Updates on the vulnerability fix can be tracked on the pages: Debian, Ubuntu, Gentoo, RHEL, Fedora, SUSE/openSUSE, Arch.

  • A vulnerability (CVE not yet assigned) in the implementation of the asynchronous input/output interface io_uring, which has been part of the Linux kernel since the 5.1 release. The problem is caused by an error in the io_sqe_buffer_register function, which allows access to physical memory beyond the statically allocated buffer. The issue only manifests in the 6.3 branch and will be addressed in the upcoming 6.3.2 update. A working prototype of an exploit that allows executing code with kernel privileges is already available for testing.

      Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster