« Back to list

CVE-2023-53304

Status: ModifiedMedium (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_set_rbtree: fix overlap expiration walk

The lazy gc on insert that should remove timed-out entries fails to release the other half of the interval, if any.

Can be reproduced with tests/shell/testcases/sets/0044interval_overlap_0 in nftables.git and kmemleak enabled kernel.

Second bug is the use of rbe_prev vs. prev pointer. If rbe_prev() returns NULL after at least one iteration, rbe_prev points to element that is not an end interval, hence it should not be removed.

Lastly, check the genmask of the end interval if this is active in the current generation.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2023-53304",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-53304",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-14T18:22:49.464474Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7ab87a326f20c52ff4d9972052d085be951c704b",
              "lessThan": "8284a79136c384059e85e278da2210b809730287",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "181859bdfb9734aca449512fccaee4cacce64aed",
              "lessThan": "acaee227cf79c45a5d2d49c3e9a66333a462802c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4aacf3d78424293e318c616016865380b37b9cc5",
              "lessThan": "893cb3c3513cf661a0ff45fe0cfa83fe27131f76",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2bf1435fa19d2c58054391b3bba40d5510a5758c",
              "lessThan": "50cbb9d195c197af671869c8cadce3bd483735a0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "318cb24a4c3fce8140afaf84e4d45fcb76fb280b",
              "lessThan": "89a4d1a89751a0fbd520e64091873e19cc0979e8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c9e6978e2725a7d4b6cd23b2facd3f11422c0643",
              "lessThan": "cd66733932399475fe933cb3ec03e687ed401462",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c9e6978e2725a7d4b6cd23b2facd3f11422c0643",
              "lessThan": "f718863aca469a109895cb855e6b81fff4827d71",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.166",
              "lessThan": "5.10.190",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.91",
              "lessThan": "5.15.124",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.9",
              "lessThan": "6.1.43",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/netfilter/nft_set_rbtree.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.190",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.124",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.43",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.4.8",
              "versionType": "semver",
              "lessThanOrEqual": "6.4.*"
            },
            {
              "status": "unaffected",
              "version": "6.5",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/netfilter/nft_set_rbtree.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-09-16T17:15:35.240",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/50cbb9d195c197af671869c8cadce3bd483735a0",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8284a79136c384059e85e278da2210b809730287",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/893cb3c3513cf661a0ff45fe0cfa83fe27131f76",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/89a4d1a89751a0fbd520e64091873e19cc0979e8",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/acaee227cf79c45a5d2d49c3e9a66333a462802c",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cd66733932399475fe933cb3ec03e687ed401462",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f718863aca469a109895cb855e6b81fff4827d71",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_rbtree: fix overlap expiration walk\n\nThe lazy gc on insert that should remove timed-out entries fails to release\nthe other half of the interval, if any.\n\nCan be reproduced with tests/shell/testcases/sets/0044interval_overlap_0\nin nftables.git and kmemleak enabled kernel.\n\nSecond bug is the use of rbe_prev vs. prev pointer.\nIf rbe_prev() returns NULL after at least one iteration, rbe_prev points\nto element that is not an end interval, hence it should not be removed.\n\nLastly, check the genmask of the end interval if this is active in the\ncurrent generation."
    }
  ],
  "lastModified": "2026-06-17T06:44:47.790",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D120E24C-92C4-42C2-BDBC-2DA33FB84683",
              "versionEndExcluding": "5.10.190",
              "versionStartIncluding": "5.10.166"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C579EE5-29AE-450E-A284-D7401ABCD1D3",
              "versionEndExcluding": "5.15.124",
              "versionStartIncluding": "5.15.91"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBB03740-07A5-4A80-A087-A4A2B6127646",
              "versionEndExcluding": "6.1.43",
              "versionStartIncluding": "6.1.9"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED5C51C1-C86A-404D-A81F-10761E602032",
              "versionEndExcluding": "6.4.8",
              "versionStartIncluding": "6.2.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3ADCCCEE-143A-4B48-9B2A-0CB97BD385DE"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.2:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4AB8D555-648E-4F2F-98BD-3E7F45BD12A8"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.2:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C64BDD9D-C663-4E75-AE06-356EDC392B82"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.2:rc8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26544390-88E4-41CA-98BF-7BB1E9D4E243"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.5:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B3E6E4D-E24E-4630-B00C-8C9901C597B0"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.5:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4A01A71-0F09-4DB2-A02F-7EFFBE27C98D"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.5:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5608371-157A-4318-8A2E-4104C3467EA1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}