.. / CVE-2023-35001

Exploit for Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability - Local Privilege Escalation (CVE-2023-35001)

Description:

Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace

Proof of Concept

PoC exploit

Try the exploit in a lab environment:

Lab Machine Link
Hack The Box Hospital Go to Practice

References:

https://nvd.nist.gov/vuln/detail/CVE-2023-35001
https://packetstormsecurity.com/files/173757/Kernel-Live-Patch-Security-Notice-LSN-0096-1.html
https://packetstormsecurity.com/files/174577/Kernel-Live-Patch-Security-Notice-LSN-0097-1.html