← Back to CVE List
Vulnerability Intelligence Report
Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()

CVE-2023-4004

A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.96%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-416 ↗Use After Free

Affected Products & Versions

Vendor Product Affected Versions
Red Hat Red Hat Enterprise Linux 8 0:4.18.0-477.27.1.rt7.290.el8_8 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8 all
Red Hat Red Hat Enterprise Linux 8 0:4.18.0-477.27.1.el8_8 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support 0:4.18.0-193.119.1.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Telecommunications Update Service 0:4.18.0-193.119.1.rt13.170.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Telecommunications Update Service 0:4.18.0-193.119.1.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions all
Red Hat Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions 0:4.18.0-193.119.1.el8_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:4.18.0-305.103.1.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service 0:4.18.0-305.103.1.rt7.178.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service 0:4.18.0-305.103.1.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions 0:4.18.0-305.103.1.el8_4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions all
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support all
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support 0:4.18.0-372.75.1.el8_6 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9 0:5.14.0-284.30.1.el9_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9 0:5.14.0-284.30.1.rt14.315.el9_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9 0:5.14.0-284.30.1.el9_2 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9 all
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support 0:5.14.0-70.80.1.el9_0 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support 0:5.14.0-70.80.1.rt21.151.el9_0 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support all
Red Hat Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 0:4.18.0-372.75.1.el8_6 < * (unaffected)
Red Hat Red Hat Enterprise Linux 6 all
Red Hat Red Hat Enterprise Linux 7 all
Red Hat Red Hat Enterprise Linux 7 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.958%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2023-07-30T11:58:17
Published2023-07-31T16:22:18
Patch Date2023-07-19
Last Updated2025-11-08T03:13:35

LINK COPIED TO CLIPBOARD