CVE-2023-3390 is an important-severity use-after-free flaw in the Linux kernel's Netfilter/nftables subsystem. Improper handling of named and anonymous sets in batch requests can allow a local attacker with CAP_NET_ADMIN to read and write arbitrary kernel memory, potentially causing denial of service or escalating privileges. Red Hat rates the vulnerability CVSS 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Unprivileged user namespaces can enable local unprivileged RHEL users to obtain the capability needed for exploitation. Red Hat released fixes for affected RHEL 8 kernel, kernel-rt, and kpatch packages, with updates issued from September 2023 through March 2024. OpenShift control-plane hosts contain the affected component, but Red Hat assesses container exploitation risk as low because OpenShift namespace controls prevent containers from obtaining the required capability.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHEL 7 kernel, kernel-rt, and kpatch-patch fixes for CVE-2023-32233 through RHSA-2023:5622, RHSA-2023:5621, and RHSA-2023:5574. The updates addressed a Netfilter nf_tables use-after-free flaw that could enable kernel-memory reads and writes for a local attacker with CAP_NET_ADMIN.
Red Hat issued fixes for RHEL 8 kernel, kernel-rt, and kpatch-patch packages through RHSA-2023:5244, RHSA-2023:5255, and RHSA-2023:5221. RHEL 8.1 Update Services for SAP Solutions also received kernel and kpatch-patch fixes via RHSA-2023:5238 and RHSA-2023:5235.
Red Hat released RHEL 8.2 kernel fixes through RHSA-2024:1268 and a Telecommunications Update Service kernel-rt fix through RHSA-2024:1269. It also issued a kpatch-patch fix for RHEL 8.2 Update Services for SAP Solutions via RHSA-2024:1278.
Alagu M of the Salesforce Offensive Security team reported CVE-2023-3390, a use-after-free flaw in Netfilter handling of named and anonymous nftables sets in batch requests. A local attacker with CAP_NET_ADMIN could obtain arbitrary kernel-memory reads and writes, potentially causing denial of service or privilege escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.