CVE-2023-53566 - CVE House
Back to Database
Status published Unknown CVE-2023-53566

netfilter: nft_set_rbtree: fix null deref on element insertion

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix null deref on element insertion There is no guarantee that rb_prev() will not return NULL in nft_rbtree_gc_elem(): general protection fault, probably for non-canonical address 0xdffffc0000000003: 0000 [#1] PREEMPT SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f] nft_add_set_elem+0x14b0/0x2990 nf_tables_newsetelem+0x528/0xb30 Furthermore, there is a possible use-after-free while iterating, 'node' can be free'd so we need to cache the next value to use.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53566

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
7ab87a326f20c52ff4d9972052d085be951c704b, 181859bdfb9734aca449512fccaee4cacce64aed, 4aacf3d78424293e318c616016865380b37b9cc5, 2bf1435fa19d2c58054391b3bba40d5510a5758c, 318cb24a4c3fce8140afaf84e4d45fcb76fb280b, c9e6978e2725a7d4b6cd23b2facd3f11422c0643, 5.10.166, 5.15.91, 6.1.9, 6.2, 0, 5.10.181, 5.15.113, 6.1.30, 6.3.4, 6.4

Timeline

Official Publish: October 4th, 2025
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.