CVE-2023-6040: Debian Linux
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) values within `nf_tables_newtable` function enables an attacker to achieve out-of-bounds access.
Affected products
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: from 4.16, before 4.19.305 (fixed in 4.19.305); from 4.20, before 5.4.267 (fixed in 5.4.267); from 5.5, before 5.10.208 (fixed in 5.10.208); from 5.11, before 5.15.147 (fixed in 5.15.147); from 5.16, before 5.18 (fixed in 5.18)
Published 2024-01-12. Last modified 2026-06-17.