A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2024:2394 | |
https://access.redhat.com/security/cve/CVE-2023-42756 | Patch Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2239848 | Exploit Issue Tracking Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GISYSL3F6WIEVGHJGLC2MFNTUXHPTKQH/ | Mailing List |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GPMICQ2HVZO5UAM5KPXHAZKA2U3ZDOO6/ | Mailing List |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V5PDNWPKAP3WL5RQZ4RIDS6MG32OHH5R/ | Mailing List |
https://seclists.org/oss-sec/2023/q3/242 | Exploit Mailing List Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2023-09-28T13:55:37.430Z
Updated: 2024-05-01T20:21:08.205Z
Reserved: 2023-09-13T11:03:47.962Z
Link: CVE-2023-42756
JSON object: View
NVD Information
Status : Modified
Published: 2023-09-28T14:15:21.037
Modified: 2024-04-30T14:15:09.243
Link: CVE-2023-42756
JSON object: View
Redhat Information
No data.
CWE