In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: disallow timeout for anonymous sets
Never used from userspace, disallow these parameters.
{ "vanir_signatures": [ { "digest": { "line_hashes": [ "242396549597457470540424951274561103460", "181329990165653878011416421930004819209", "114562281641740913903969999745393853547", "26377982946989713042035401922794109012", "99137027159514844088150537781683102044", "142674434258183032597084162626473018073", "40517865433180584429895737804620793032" ], "threshold": 0.9 }, "target": { "file": "net/netfilter/nf_tables_api.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@49ce99ae43314d887153e07cec8bb6a647a19268", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-52620-0ca10372" }, { "digest": { "line_hashes": [ "242396549597457470540424951274561103460", "181329990165653878011416421930004819209", "114562281641740913903969999745393853547", "26377982946989713042035401922794109012", "99137027159514844088150537781683102044", "142674434258183032597084162626473018073", "40517865433180584429895737804620793032" ], "threshold": 0.9 }, "target": { "file": "net/netfilter/nf_tables_api.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@116b0e8e4673a5faa8a739a19b467010c4d3058c", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-52620-3972c349" }, { "digest": { "line_hashes": [ "171026657143504280614990224346061882472", "1794548213667286605909602527226012568", "173622775269436625025738803627404457562", "302393162046695980023694353107860235587", "321061273119469399458059579049186575174", "49098055705409756563907524339296068267", "334447982083797983577533271223206988016" ], "threshold": 0.9 }, "target": { "file": "net/netfilter/nf_tables_api.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e26d3009efda338f19016df4175f354a9bd0a4ab", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-52620-3ad5b48c" }, { "digest": { "line_hashes": [ "242396549597457470540424951274561103460", "181329990165653878011416421930004819209", "114562281641740913903969999745393853547", "26377982946989713042035401922794109012", "99137027159514844088150537781683102044", "142674434258183032597084162626473018073", "40517865433180584429895737804620793032" ], "threshold": 0.9 }, "target": { "file": "net/netfilter/nf_tables_api.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6f3ae02bbb62f151b19162d5fdc9fe3d48450323", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-52620-70c73d3e" }, { "digest": { "line_hashes": [ "171026657143504280614990224346061882472", "1794548213667286605909602527226012568", "173622775269436625025738803627404457562", "302393162046695980023694353107860235587", "321061273119469399458059579049186575174", "49098055705409756563907524339296068267", "334447982083797983577533271223206988016" ], "threshold": 0.9 }, "target": { "file": "net/netfilter/nf_tables_api.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@00b19ee0dcc1aef06294471ab489bae26d94524e", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-52620-8bcc8334" }, { "digest": { "line_hashes": [ "171026657143504280614990224346061882472", "1794548213667286605909602527226012568", "173622775269436625025738803627404457562", "302393162046695980023694353107860235587", "321061273119469399458059579049186575174", "49098055705409756563907524339296068267", "334447982083797983577533271223206988016" ], "threshold": 0.9 }, "target": { "file": "net/netfilter/nf_tables_api.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7be6c737a179a76901c872f6b4c1d00552d9a1b", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-52620-a73fc18d" } ] }