CVE-2023-5197: Debian Linux
Medium severity, CVSS 6.6. EPSS: 0.4% chance of exploitation in the next 30 days.
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free. We recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.
Affected products
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: from 5.9.0, before 5.10.198 (fixed in 5.10.198); from 5.11, before 5.15.134 (fixed in 5.15.134); from 5.16, before 6.1.56 (fixed in 6.1.56); from 6.2, before 6.5.6 (fixed in 6.5.6)
Published 2023-09-27. Last modified 2026-06-17.