CVE-2023-53701

Source
https://cve.org/CVERecord?id=CVE-2023-53701
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53701.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-53701
Downstream
Published
2025-10-22T13:23:40Z
Modified
2026-04-10T05:06:58.968208Z
Summary
netfilter: nf_tables: deactivate anonymous set from preparation phase
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: deactivate anonymous set from preparation phase

[ backport for 4.14 of c1592a89942e9678f7d9c8030efa777c0d57edab ]

Toggle deleted anonymous sets as inactive in the next generation, so users cannot perform any update on it. Clear the generation bitmask in case the transaction is aborted.

The following KASAN splat shows a set element deletion for a bound anonymous set that has been already removed in the same transaction.

[ 64.921510] ================================================================== [ 64.923123] BUG: KASAN: wild-memory-access in nftablescommit+0xa24/0x1490 [nftables] [ 64.924745] Write of size 8 at addr dead000000000122 by task test/890 [ 64.927903] CPU: 3 PID: 890 Comm: test Not tainted 6.3.0+ #253 [ 64.931120] Call Trace: [ 64.932699] <TASK> [ 64.934292] dumpstacklvl+0x33/0x50 [ 64.935908] ? nftablescommit+0xa24/0x1490 [nftables] [ 64.937551] kasanreport+0xda/0x120 [ 64.939186] ? nftablescommit+0xa24/0x1490 [nftables] [ 64.940814] nftablescommit+0xa24/0x1490 [nf_tables] [ 64.942452] ? __kasanslaballoc+0x2d/0x60 [ 64.944070] ? nftablessetelemnotify+0x190/0x190 [nftables] [ 64.945710] ? kasansettrack+0x21/0x30 [ 64.947323] nfnetlinkrcvbatch+0x709/0xd90 [nfnetlink] [ 64.948898] ? nfnetlinkrcvmsg+0x480/0x480 [nfnetlink]

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
86572872505023e3bb461b271c2f25fdaa3dfcd7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53701.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.14.315

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53701.json"