CVE-2023-4569 is a memory leak flaw in the Linux Kernel's nft_set_catchall_flush function, affecting various Debian and Red Hat Linux distributions. A local attacker could exploit this vulnerability to trigger double-deactivations of catchall elements, leading to a memory leak. Rated with a CVSS score of 5.5 (MEDIUM), this vulnerability requires local access and has a high impact on availability, though confidentiality and integrity are not affected. There is currently no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.5:rc1:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.5:rc2:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.5:rc3:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.5:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-4569
Sep 12, 2023kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c
Aug 12, 2023Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c
Aug 8, 2023