CVE-2023-42753 is a high-severity Linux kernel Netfilter flaw in the hash:net,port,net ipset implementation. A missing IP_SET_HASH_WITH_NET0 macro causes an incorrect CIDR_POS(c) array-offset calculation, permitting integer underflow and an out-of-bounds increment or decrement of the h->nets array. A local low-privileged attacker could crash an affected system and potentially elevate privileges; Red Hat rated the issue CVSS 7.0, while NVD assigned 7.8.
Upstream corrected the defect in commit 050d91c03b28ca479df13dfb02bcd2c60dd6a878, with Fedora including the fix in kernel 6.5.3. Red Hat issued updates across affected RHEL 7, 8, and 9 package streams, including RHEL 8.8 live-kernel patches delivered through RHSA-2023:7558; the kpatch-patch modules load automatically and apply the fix without a conventional reboot. No practical mitigation is available, so organizations should update affected kernel packages promptly; RHEL 7.6 was assessed as unaffected because it rejects /0 netmasks.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:0376, an Important kpatch-patch live-kernel update for RHEL 8.2 Update Services for SAP Solutions on x86_64 and Power LE ppc64le. The update remediated CVE-2023-42753 alongside CVE-2023-4622 and CVE-2023-2163 without requiring a conventional reboot.
Red Hat released RHSA-2024:0346 and RHSA-2024:0347 for RHEL 7 kernel and kernel-rt packages, plus RHSA-2024:0371 for the RHEL 7 kpatch-patch package, to remediate CVE-2023-42753.
Red Hat published RHSA-2023:7558, an Important advisory providing updated kpatch-patch live kernel modules for RHEL 8.8 support channels. The update addressed CVE-2023-42753 along with five other Linux kernel vulnerabilities and could patch running kernels without a conventional reboot.
Red Hat released RHSA-2024:0999 to fix CVE-2023-42753 in the RHEL 7.7 Advanced Update Support kernel.
Red Hat issued RHSA-2024:0403 for RHEL 8.2 Advanced Update Support and RHSA-2024:0402 and RHSA-2024:0403 for RHEL 8.2 Telecommunications Update Service, addressing CVE-2023-42753 in affected kernel packages.
Red Hat issued fixes for RHEL 9.2 and 9.0 Extended Update Support through RHSA-2023:7379, RHSA-2023:7370, RHSA-2023:7418, RHSA-2023:7389, RHSA-2023:7382, and RHSA-2023:7411.
The upstream Linux kernel corrected the Netfilter issue in commit 050d91c03b28ca479df13dfb02bcd2c60dd6a878. Fedora subsequently delivered the correction in stable Linux kernel 6.5.3 updates.
A missing IP_SET_HASH_WITH_NET0 macro in the Netfilter ipset hash:net,port,net implementation could cause an integer underflow and slab out-of-bounds memory access when handling /0 CIDR netmasks. A local low-privileged attacker could potentially crash an affected system or escalate privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.