CVE-2023-0179 is a high-severity buffer overflow vulnerability in the Netfilter subsystem of the Linux Kernel, affecting distributions like Canonical, Fedora, and Red Hat. This flaw allows a local attacker to leak stack and heap addresses, potentially leading to local privilege escalation to root through arbitrary code execution. While there is no evidence of active exploitation in the wild and no public exploit code in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion, including a proof-of-concept and write-up on Reddit and Hackernews.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.5.0, < 5.10.164CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.89CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-0179
May 9, 2023A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
Mar 14, 2023kernel: Netfilter integer overflow vulnerability in nft_payload_copy_vlan
Jan 13, 2023