CVE-2023-3610
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jul 21, 2023
Updated: Dec 29, 2023
CWE ID 416
Summary
CVE-2023-3610 is a local privilege escalation vulnerability affecting the Linux kernel's netfilter: nf_tables component. This issue is caused by a use-after-free flaw in the error handling of bound chains, specifically in the NFT_MSG_NEWRULE function. Exploitation of this vulnerability requires the CAP_NET_ADMIN capability. To mitigate this risk, it is recommended to upgrade to a version past commit 4bedf9eee016286c835e3d8fa981ddece5338795.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.