A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the system.
| Software | From | Fixed in |
|---|---|---|
| fedoraproject / fedora | 38 | 38.x |
| redhat / enterprise_linux | 8.0 | 8.0.x |
| redhat / enterprise_linux | 9.0 | 9.0.x |
| linux / linux_kernel | 5.16 | 6.1.42 |
| linux / linux_kernel | 5.11 | 5.15.123 |
| linux / linux_kernel | 5.6 | 5.10.188 |
| linux / linux_kernel | 6.2 | 6.4.7 |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |
| debian / debian_linux | 12.0 | 12.0.x |