A use-after-free flaw in the Linux kernel's Netfilter nftables nft_pipapo_walk function, tracked as CVE-2023-6817, can allow a local attacker with CAP_NET_ADMIN to crash a host, disclose information, or elevate privileges. The defect allowed inactive PIPAPO set elements to be processed and deactivated twice during a set walk, leading to a kernel crash; it carries a CVSS v3.1 score of 7.8.
Linux kernel commit 317eb9685095678f2c9f5a8189de698c5354316a fixes the issue by verifying that an element is active before invoking the iterator callback. Red Hat issued fixes for affected RHEL 8 kernel and kernel-rt packages; systems with unprivileged user namespaces enabled may let unprivileged users obtain the required capability. OpenShift Container Platform inherits the affected code through RHCOS, but Red Hat rates impact as Low because its namespace model prevents containers from acquiring the capabilities needed to exploit the flaw.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:0897 for affected RHEL 8 kernel packages and RHSA-2024:0881 for RHEL 8 kernel-rt packages, fixing CVE-2023-6817.
Florian Westphal authored a patch to skip inactive nftables pipapo set elements during set walks, preventing their double deactivation and resulting kernel crash. Xingyuan Mo reported the issue.
Red Hat released RHSA-2024:1367 for RHEL 8.4 Advanced Mission Critical Update Support kernel packages and RHSA-2024:1382 for RHEL 8.4 Telecommunications Update Service kernel-rt packages.
Red Hat fixed affected RHEL 8.2 Advanced Update Support kernel packages in RHSA-2024:1268 and Telecommunications Update Service kernel-rt packages in RHSA-2024:1269.
Pablo Neira Ayuso committed upstream Linux commit 317eb9685095678f2c9f5a8189de698c5354316a, which checks whether an element is active before invoking the nft_pipapo_walk iterator callback.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcegit.kernel.org
Open sourcepatchwork.ozlabs.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.