{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2023-54035",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-12-24T10:53:46.180Z",
        "datePublished": "2025-12-24T10:56:02.358Z",
        "dateUpdated": "2026-08-05T09:16:39.727Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T09:16:39.727Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix underflow in chain reference counter\n\nSet element addition error path decrements reference counter on chains\ntwice: once on element release and again via nft_data_release().\n\nThen, d6b478666ffa (\"netfilter: nf_tables: fix underflow in object\nreference counter\") incorrectly fixed this by removing the stateful\nobject reference count decrement.\n\nRestore the stateful object decrement as in b91d90368837 (\"netfilter:\nnf_tables: fix leaking object reference count\") and let\nnft_data_release() decrement the chain reference counter, so this is\ndone only once."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerability is reached via the nfnetlink/netlink socket interface (NFT_MSG_NEWSETELEM), a local kernel API with no remote/network reachability.\nAC:L - The attacker deterministically reaches the buggy error path (e.g., inserting a duplicate map element to force -EEXIST) and controls how many times to repeat it; no uncontrolled conditions are involved.\nPR:L - nf_tables requires CAP_NET_ADMIN, but an unprivileged user obtains this in a new network namespace via unshare -Urn, so only low privileges are needed.\nUI:N - The counter underflow and subsequent chain deletion are triggered entirely by the attacker's own netlink operations, with no victim interaction required.\nS:U - The impact stays within the kernel's security authority (local privilege escalation), not crossing into a separate security scope such as a hypervisor boundary.\nC:H - The chain refcount underflow leads to a use-after-free of the chain object, letting the attacker reclaim the freed slot and read sensitive kernel memory.\nI:H - The use-after-free provides heap write primitives via reclaiming the freed chain object, enabling arbitrary memory corruption and privilege escalation.\nA:H - Freeing a still-referenced chain leaves dangling pointers that cause use-after-free access and kernel panic/oops."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/netfilter/nf_tables_api.c"
                    ],
                    "versions": [
                        {
                            "version": "35651fde1a7bb54dde0a46d35cd0d7136869ae86",
                            "lessThan": "b068314fd8ce751a7f906e55bb90f3551815f1a0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "628bd3e49cba1c066228e23d71a852c23e26da73",
                            "lessThan": "9c959671abc7d4ffdf34eed10c64492d43cb6a3c",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "628bd3e49cba1c066228e23d71a852c23e26da73",
                            "lessThan": "b389139f12f287b8ed2e2628b72df89a081f0b59",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "bc9f791d2593f17e39f87c6e2b3a36549a3705b1",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "3c7ec098e3b588434a8b07ea9b5b36f04cef1f50",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a136b7942ad2a50de708f76ea299ccb45ac7a7f9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "25aa2ad37c2162be1c0bc4fe6397f7e4c13f00f8",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d60be2da67d172aecf866302c91ea11533eca4d9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "dc7cdf8cbcbf8b13de1df93f356ec04cdeef5c41",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "4.19.316",
                            "lessThan": "4.20",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.262",
                            "lessThan": "5.5",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.188",
                            "lessThan": "5.11",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.121",
                            "lessThan": "5.16",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.3.10",
                            "lessThan": "6.4",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/netfilter/nf_tables_api.c"
                    ],
                    "versions": [
                        {
                            "version": "6.4",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.4",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.4.4",
                            "lessThanOrEqual": "6.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.5",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.4",
                                    "versionEndExcluding": "6.4.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.4",
                                    "versionEndExcluding": "6.5"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.19.316"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4.262"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10.188"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15.121"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.3.10"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/b068314fd8ce751a7f906e55bb90f3551815f1a0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9c959671abc7d4ffdf34eed10c64492d43cb6a3c"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b389139f12f287b8ed2e2628b72df89a081f0b59"
                }
            ],
            "title": "netfilter: nf_tables: fix underflow in chain reference counter",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}