Red Hat addressed CVE-2023-35001, a high-severity out-of-bounds memory-access vulnerability in the Linux kernel Netfilter nf_tables implementation, specifically the nft_byteorder_eval() function. Failed bounds checking and incorrect data alignment can allow an attacker holding CAP_NET_ADMIN in a user or network namespace to escalate privileges locally; Red Hat assigned a CVSS v3.1 score of 7.8, with high impacts to confidentiality, integrity, and availability.
Affected Red Hat Enterprise Linux 7 and 8 kernel, real-time kernel, and kpatch packages received fixes through 2023 advisories. RHSA-2023:7243 supplies fixed 3.10.0-1062.80.1.el7 kernel packages for RHEL 7.7 AUS on x86_64; organizations must reboot after installation. Until updates can be deployed, Red Hat recommends blacklisting the affected Netfilter kernel module to prevent it from loading.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2023:5621, RHSA-2023:5574, and RHSA-2023:5622 to remediate CVE-2023-35001 in RHEL 7 kernel-rt, kpatch-patch, and kernel packages.
Red Hat released RHSA-2023:5414, providing a kernel fix for CVE-2023-35001 for Red Hat Enterprise Linux 7.6 Advanced Update Support.
Red Hat issued RHSA-2023:5255, RHSA-2023:5221, RHSA-2023:5244, RHSA-2023:5235, and RHSA-2023:5238 to fix CVE-2023-35001 in RHEL 8 kernel, kernel-rt, and kpatch packages, including RHEL 8.1 Update Services for SAP Solutions.
Red Hat published Important advisory RHSA-2023:7243 for RHEL Server AUS 7.7 on x86_64, fixing the nft_byteorder_eval stack out-of-bounds read tracked as CVE-2023-35001. The update provides kernel version 3.10.0-1062.80.1.el7 and requires a reboot for the fix to take effect.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.