CVE-2023-31248: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 1.9% chance of exploitation in the next 30 days.
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only; version 22.04 only
- Debian Debian Linux: version 11.0 only
- Fedoraproject Fedora: version 37 only; version 38 only
- Linux Linux Kernel: from 5.9, before 5.10.188 (fixed in 5.10.188); from 5.11, before 5.15.121 (fixed in 5.15.121); from 5.16, before 6.1.39 (fixed in 6.1.39); from 6.2, before 6.4.4 (fixed in 6.4.4)
Published 2023-07-05. Last modified 2026-06-17.