Tracker / CVE-2024-0193
CVE-2024-0193
High 7.8
A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user with CAP_NET_ADMIN capability to escalate their privileges on the system.
Affected products and versions
| linux | linux_kernel · 5.10.198 → 5.10.206 |
|---|---|
| linux | linux_kernel · 5.15.118 → 5.15.146 |
| linux | linux_kernel · 6.1.35 → 6.1.71 |
| linux | linux_kernel · 6.3.9 → 6.6.10 |
| redhat | codeready_linux_builder |
| redhat | codeready_linux_builder_for_eus |
| redhat | codeready_linux_builder_for_ibm_z_systems |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus |
| redhat | codeready_linux_builder_for_power_little_endian |
| redhat | codeready_linux_builder_for_power_little_endian_eus |
| redhat | enterprise_linux |
| redhat | enterprise_linux_for_arm_64 |
| redhat | enterprise_linux_for_arm_64_els |
| redhat | enterprise_linux_for_arm_64_eus |
| redhat | enterprise_linux_for_els |
| redhat | enterprise_linux_for_eus |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_ibm_z_systems_els |
| redhat | enterprise_linux_for_ibm_z_systems_eus |
| redhat | enterprise_linux_for_power_little_endian_els |
| redhat | enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise_linux_for_update_services_for_sap_solutions |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions |
| redhat | openshift_logging · 5.0 → 5.8.6 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.