HIGH 7.8 Microsoft PoC

CVE-2023-32233

In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

Microsoft Security Update 2023-May: In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.

Affected Products

References

Published: 2023-05-09 · Source: Microsoft · Feed updated: 2026-09-03
This high severity vulnerability with a CVSS score of 7.8 was published on 2023-05-09 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 13.0% (top 4% of all CVEs by exploitation probability). Affected: cm1 kernel 5.10.181.1-1 on CBL Mariner 1.0, cbl2 kernel 5.15.112.1-1 on CBL Mariner 2.0.
vulnfeed aggregates 7805 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.