
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-52925 is a vulnerability in the Linux kernel's netfilter nf_tables component, discovered and disclosed on February 5, 2025. The issue specifically affects the handling of expired duplicate entries in nftables, where the system incorrectly fails inserts when duplicate entries have expired (NVD, RedHat).
The vulnerability stems from incorrect handling of expired elements in the nft_pipapo_get function within the Linux kernel's netfilter subsystem. The issue causes nftables selftests to fail, specifically in the testcase 'sets/0044interval_overlap_0'. The CVSS v3.1 score is 6.2 (Medium), with a vector string of CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating local access is required but no privileges are needed (Kernel Commit).
The vulnerability affects the availability of the system's netfilter functionality. When exploited, it can cause insertion operations to fail incorrectly when dealing with expired duplicate entries in nftables, potentially disrupting network filtering operations (RedHat).
The issue has been resolved in the Linux kernel through a patch that modifies the behavior of nft_pipapo_get to properly handle expired elements. The fix includes changes to ensure that insertion operations ignore duplicate but expired entries (Kernel Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."