Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-3390

28
FAUCET Score

CVE-2023-3390 is a use-after-free vulnerability in the Linux kernel's netfilter subsystem, specifically in net/netfilter/nf_tables_api.c, affecting Linux and NetApp products. This flaw stems from mishandled error handling with NFT_MSG_NEWRULE, leading to a dangling pointer that can be exploited within the same transaction. With a CVSS score of 7.8 (HIGH), a local attacker with user access can leverage this vulnerability to achieve privilege escalation, resulting in high impact to confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.16, < 4.14.322CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.291CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.188CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.118CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.251CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.91%
Probability of exploitation in next 30 days
EPSS Percentile
56.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0091 is in the 91st percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (25)

microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.122.1-2 on CBL Mariner 2.0Fixed in: 5.15.122.1-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-477.27.1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-147.90.1.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: kernel-0:4.18.0-193.128.1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: kernel-rt-0:4.18.0-193.128.1.rt13.179.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: kernel-0:4.18.0-193.128.1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-193.128.1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-305.103.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: kernel-rt-0:4.18.0-305.103.1.rt7.178.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-477.27.1.rt7.290.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-305.103.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: kernel-0:4.18.0-372.70.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-284.30.1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt-0:5.14.0-284.30.1.rt14.315.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: kernel-0:5.14.0-70.93.2.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: kernel-rt-0:5.14.0-70.93.1.rt21.165.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-372.70.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: kernel-0:4.18.0-305.103.1.el8_4
View patch

Vendor Advisories (2)

microsoft2023-Jun/CVE-2023-3390Important

Use-after-free in Linux kernel's netfilter subsystem

Jun 13, 2023
redhatCVE-2023-3390Important

kernel: UAF in nftables when nft_set_lookup_global triggered after handling named and anonymous sets in batch requests

Jun 8, 2023

References

packetstormsecurity.com / files/174577/Kernel-Live-Patch-Security-Notice-LSN-0097-1.html
Third Party AdvisoryVDB Entry
debian.org / security/2023/dsa-5448
Third Party Advisory
debian.org / security/2023/dsa-5461
Third Party Advisory
git.kernel.org / pub/scm/linux/kernel/git/stable/linux.git/commit
Mailing ListPatch
kernel.dance / 1240eb93f0616b21c675416516ff3d74798fdc97
Patch
lists.debian.org / debian-lts-announce/2023/08/msg00001.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2024/01/msg00004.html
Third Party AdvisoryVDB Entry
lists.debian.org / debian-security-announce/2023/msg00140.html
lists.debian.org / debian-security-announce/2023/msg00153.html
packetstorm.news / tos/aHR0cHM6Ly9wYWNrZXRzdG9ybS5uZXdzL2ZpbGVzLzE3NDU3Ny9LZXJuZWwtTGl2ZS1QYXRjaC1TZWN1cml0eS1Ob3RpY2UtTFNOLTAwOTctMS5odG1sIDE3ODQ3MjE0NzIgODFlMjk3ZjBmM2FiMTIwOTI5Nzg0ZmRlNGM2NWNjNjBhMThhMzBiOGE5NjQ0YzQ0NTFhMzJlZjhiNTk1ZTk2Yg==
security.netapp.com / advisory/ntap-20230818-0004
Third Party Advisory