Vulnerability Description
An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) values within `nf_tables_newtable` function enables an attacker to achieve out-of-bounds access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.16, < 4.19.305 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/177029/Kernel-Live-Patch-Security-Notice-LSThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2024/01/12/1Mailing ListPatchThird Party Advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6040Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00016.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlMailing ListThird Party Advisory
- https://www.openwall.com/lists/oss-security/2024/01/12/1Mailing ListThird Party Advisory
- http://packetstormsecurity.com/files/177029/Kernel-Live-Patch-Security-Notice-LSThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2024/01/12/1Mailing ListPatchThird Party Advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6040Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00016.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlMailing ListThird Party Advisory
- https://www.openwall.com/lists/oss-security/2024/01/12/1Mailing ListThird Party Advisory
FAQ
What is CVE-2023-6040?
CVE-2023-6040 is a vulnerability with a CVSS score of 7.8 (HIGH). An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lac...
How severe is CVE-2023-6040?
CVE-2023-6040 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6040?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.