In the Linux kernel, the following vulnerability has been resolved:
netfilter: nftsetrbtree: skip sync GC for new elements in this transaction
New elements in this transaction might expired before such transaction ends. Skip sync GC for such elements otherwise commit path might walk over an already released object. Once transaction is finished, async GC will collect such expired element.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2ee52ae94baabf7ee09cf2a8d854b990dac5d0e4",
"id": "CVE-2023-52433-27092613",
"deprecated": false,
"target": {
"file": "net/netfilter/nft_set_rbtree.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"155964969111766675669640948764958559175",
"149660186107941586891329850074911777185",
"245098455786942868018242881929486757340",
"97150325067326974543422835126779128750",
"79555213799250054126138380546538499715",
"337642283389850677232670235559580447012",
"161917979047577122507517229249567744672",
"210014254055008252939200884492362109515"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9db9feb841f7449772f9393c16b9ef4536d8c127",
"id": "CVE-2023-52433-2c2bacaa",
"deprecated": false,
"target": {
"file": "net/netfilter/nft_set_rbtree.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"155964969111766675669640948764958559175",
"149660186107941586891329850074911777185",
"245098455786942868018242881929486757340",
"97150325067326974543422835126779128750",
"79555213799250054126138380546538499715",
"337642283389850677232670235559580447012",
"161917979047577122507517229249567744672",
"210014254055008252939200884492362109515"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e3213ff99a355cda811b41e8dbb3472d13167a3a",
"id": "CVE-2023-52433-376742c7",
"deprecated": false,
"target": {
"file": "net/netfilter/nft_set_rbtree.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"155964969111766675669640948764958559175",
"149660186107941586891329850074911777185",
"245098455786942868018242881929486757340",
"97150325067326974543422835126779128750",
"79555213799250054126138380546538499715",
"337642283389850677232670235559580447012",
"161917979047577122507517229249567744672",
"210014254055008252939200884492362109515"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9a8c544158f68f656d1734eb5ba00c4f817b76b1",
"id": "CVE-2023-52433-4b444321",
"deprecated": false,
"target": {
"file": "net/netfilter/nft_set_rbtree.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"155964969111766675669640948764958559175",
"149660186107941586891329850074911777185",
"245098455786942868018242881929486757340",
"97150325067326974543422835126779128750",
"79555213799250054126138380546538499715",
"337642283389850677232670235559580447012",
"161917979047577122507517229249567744672",
"210014254055008252939200884492362109515"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@03caf75da1059f0460666c826e9f50e13dfd0017",
"id": "CVE-2023-52433-64e4d117",
"deprecated": false,
"target": {
"file": "net/netfilter/nft_set_rbtree.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"155964969111766675669640948764958559175",
"149660186107941586891329850074911777185",
"245098455786942868018242881929486757340",
"97150325067326974543422835126779128750",
"79555213799250054126138380546538499715",
"337642283389850677232670235559580447012",
"161917979047577122507517229249567744672",
"210014254055008252939200884492362109515"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c323ed65f66e5387ee0a73452118d49f1dae81b8",
"id": "CVE-2023-52433-8f0c20a7",
"deprecated": false,
"target": {
"file": "net/netfilter/nft_set_rbtree.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"155964969111766675669640948764958559175",
"149660186107941586891329850074911777185",
"245098455786942868018242881929486757340",
"97150325067326974543422835126779128750",
"79555213799250054126138380546538499715",
"337642283389850677232670235559580447012",
"161917979047577122507517229249567744672",
"210014254055008252939200884492362109515"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9af7dfb3c9d7985172a240f85e684c5cd33e29ce",
"id": "CVE-2023-52433-da307bee",
"deprecated": false,
"target": {
"file": "net/netfilter/nft_set_rbtree.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"155964969111766675669640948764958559175",
"149660186107941586891329850074911777185",
"245098455786942868018242881929486757340",
"97150325067326974543422835126779128750",
"79555213799250054126138380546538499715",
"337642283389850677232670235559580447012",
"161917979047577122507517229249567744672",
"210014254055008252939200884492362109515"
]
},
"signature_type": "Line"
}
]