CVE-2023-52620 affects the Linux kernel's Netfilter nf_tables component, where a local low-privileged user could assign timeout values to anonymous sets—an unsupported state that may trigger unexpected behavior or security consequences. Red Hat rates the flaw moderate with CVSS v3.1 2.5, citing high attack complexity and low availability impact.
The upstream fix disallows timeouts for anonymous sets and is included in kernel versions 5.15.151, 6.1.81, and 6.4. Red Hat released fixes for Red Hat Enterprise Linux 8 and 9 through advisories including RHSA-2024:2394, RHSA-2024:2950, and RHSA-2024:3138; RHEL 6 and 7 kernel packages are outside support scope, and Red Hat identified no practical mitigation beyond applying updated kernel packages.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:3306 to fix CVE-2024-26642 in Red Hat Enterprise Linux 9 kernel packages. The flaw concerns anonymous nf_tables sets accepted with the timeout flag.
Red Hat released RHSA-2024:2394 to address CVE-2023-52620 in Red Hat Enterprise Linux 9 kernel packages.
The Linux kernel CVE team assigned CVE-2024-26642 for a netfilter nf_tables issue involving anonymous sets configured with the timeout flag. The upstream advisory documented a fix that disallows such anonymous timeout-enabled sets.
The Linux kernel CVE team announced CVE-2023-52620, a netfilter nf_tables issue involving timeout parameters on anonymous sets. The fix disallows those parameters, with fixes available in Linux 5.15.151, 6.1.81, and 6.4.
Marco Benatto reported Red Hat Bug 2270883 for CVE-2023-52620, affecting the Linux kernel Netfilter nf_tables subsystem. The issue involves userspace setting unsupported timeout values on anonymous sets.
Red Hat released RHSA-2024:3138 for affected RHEL 8 kernel packages and RHSA-2024:2950 for RHEL 8 kernel-rt packages, addressing CVE-2023-52620.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourcelore.kernel.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.