SB20250327153 - Buffer overflow in Linux kernel netfilter ipset
Published: March 27, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2023-53032)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to memory corruption within the bitmap_ip_create() function in net/netfilter/ipset/ip_set_bitmap_ip.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4e6a70fd840400e3a2e784a6673968a3eb2431c0
- https://git.kernel.org/stable/c/511cf17b2447fc41cfef8d71936e1fa53e395c1e
- https://git.kernel.org/stable/c/9ea4b476cea1b7d461d16dda25ca3c7e616e2d15
- https://git.kernel.org/stable/c/dfd834ccc1b88bbbab81b9046a3a539dd0c2d14f
- https://git.kernel.org/stable/c/e137d9bb26bd85ce07323a38e38ceb0b160db841
- https://git.kernel.org/stable/c/e88865876d47c790be0d5e23973499d75d034364
- https://git.kernel.org/stable/c/feefb33eefa166fc3e0fd17547b0bc0cb3baced9
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.229