CVE-2023-54035: Linux
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix underflow in chain reference counter Set element addition error path decrements reference counter on chains twice: once on element release and again via nft_data_release(). Then, d6b478666ffa ("netfilter: nf_tables: fix underflow in object reference counter") incorrectly fixed this by removing the stateful object reference count decrement. Restore the stateful object decrement as in b91d90368837 ("netfilter: nf_tables: fix leaking object reference count") and let nft_data_release() decrement the chain reference counter, so this is done only once.
Affected products
- Linux Linux: from 4.19.316, before 4.20 (fixed in 4.20); from 5.4.262, before 5.5 (fixed in 5.5); from 5.10.188, before 5.11 (fixed in 5.11); from 5.15.121, before 5.16 (fixed in 5.16); from 6.3.10, before 6.4 (fixed in 6.4); from 6.4, before 6.4.4 (fixed in 6.4.4)
Published 2025-12-24. Last modified 2026-08-04.