CVE-2023-42753: Debian Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.
Affected products
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: from 4.4.165, before 4.5 (fixed in 4.5); from 4.9.141, before 4.10 (fixed in 4.10); from 4.14.84, before 4.15 (fixed in 4.15); from 4.19.5, before 4.19.295 (fixed in 4.19.295); from 4.20, before 5.4.257 (fixed in 5.4.257); from 5.5, before 5.10.195 (fixed in 5.10.195); …
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 9.0 only
Published 2023-09-25. Last modified 2026-08-06.