kernel CVE-2023-3610
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.15.0
Patched versions
1.15.0
kernel-5.15
(bottlerocket)
< 1.15.0
1.15.0
A use-after-free vulnerability was found in the netfilter: nf_tables component in the Linux kernel due to a missing error handling in the abort path of NFT_MSG_NEWRULE. This flaw allows a local user with CAP_NET_ADMIN access capability to cause a local privilege escalation.