In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_ac
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
별도 긴급 패치 불필요 — 정기 시스템 업그레이드 주기에 맞춰 조치
CVSS 벡터 · 메트릭
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H상세 설명
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
nft_map_catchall_activate() has an inverted element activity check
compared to its non-catchall counterpart nft_mapelem_activate() and
compared to what is logically required.
nft_map_catchall_activate() is called from the abort path to re-activate
catchall map elements that were deactivated during a failed transaction.
It should skip elements that are already active (they don't need
re-activation) and process elements that are inactive (they need to be
restored). Instead, the current code does the opposite: it skips inactive
elements and processes active ones.
Compare the non-catchall activate callback, which is correct:
nft_mapelem_activate():
if (nft_set_elem_active(ext, iter->genmask))
return 0; /* skip active, process inactive */
With the buggy catchall version:
nft_map_catchall_activate():
if (!nft_set_elem_active(ext, genmask))
continue; /* skip inactive, process active */
The consequence is that when a DELSET operation is aborted,
nft_setelem_data_activate() is never called for the catchall element.
For NFT_GOTO verdict elements, this means nft_data_hold() is never
called to restore the chain->use reference count. Each abort cycle
permanently decrements chain->use. Once chain->use reaches zero,
DELCHAIN succeeds and frees the chain while catchall verdict elements
still reference it, resulting in a use-after-free.
This is exploitable for local privilege escalation from an unprivileged
user via user namespaces + nftables on distributions that enable
CONFIG_USER_NS and CONFIG_NF_TABLES.
Fix by removing the negation so the check matches nft_mapelem_activate():
skip active elements, process inactive ones.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- linux linux_kernel4.19.316 - 4.20linux
- linux linux_kernel5.4.262 - 5.5linux
- linux linux_kernel5.10.188 - 5.11linux
- linux linux_kernel5.15.121 - 5.15.200linux
- linux linux_kernel6.1.36 - 6.1.163linux
- linux linux_kernel6.3.10 - 6.4linux
- linux linux_kernel6.4.1 - 6.6.124linux
- linux linux_kernel6.7 - 6.12.70linux
- linux linux_kernel6.13 - 6.18.10linux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
- linux linux_kernellinux
영향받는 구성 (CPE) 10
- linux linux_kernel≥ 4.19.316 < 4.20cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
- linux linux_kernel 6.4cpe:2.3:o:linux:linux_kernel:6.4:-:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
- linux linux_kernel 6.19cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*
참고 자료 18
링크 내용 불러오는 중…