CVE-2023-52433
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-52433 is a vulnerability discovered in the Linux kernel's netfilter subsystem, specifically in the nft_set_rbtree component. The vulnerability was disclosed on February 20, 2024, affecting Linux kernel versions prior to 6.6-rc1. The issue occurs when new elements in a transaction might expire before the transaction ends, potentially leading to the system walking over an already released object during the commit path (NVD, Ubuntu).

Technical details

The vulnerability exists in the netfilter's nft_set_rbtree component where synchronous garbage collection (GC) incorrectly handles new elements in transactions. The issue stems from a condition where new elements might expire before their transaction completes. The CVSS v3.1 base score is 4.4 (MEDIUM) with vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H, indicating local access requirements and potential high impact on availability (NVD).

Impact

The vulnerability could lead to system instability or denial of service conditions due to the potential access of already released objects. According to security assessments, successful exploitation could result in disclosure of sensitive information, modification of data, or Denial of Service (DoS) (NetApp Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Linux kernel version 6.6-rc1 through a patch that modifies the garbage collection behavior to skip sync GC for new elements in transactions. The fix ensures that async GC will collect expired elements once the transaction is finished (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-gcp
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-modules-extra
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management