imPC@ndo IT

Tracker / CVE-2024-0193

CVE-2024-0193

High 7.8

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user with CAP_NET_ADMIN capability to escalate their privileges on the system.

Affected products and versions

linux linux_kernel · 5.10.198 → 5.10.206
linux linux_kernel · 5.15.118 → 5.15.146
linux linux_kernel · 6.1.35 → 6.1.71
linux linux_kernel · 6.3.9 → 6.6.10
redhat codeready_linux_builder
redhat codeready_linux_builder_for_eus
redhat codeready_linux_builder_for_ibm_z_systems
redhat codeready_linux_builder_for_ibm_z_systems_eus
redhat codeready_linux_builder_for_power_little_endian
redhat codeready_linux_builder_for_power_little_endian_eus
redhat enterprise_linux
redhat enterprise_linux_for_arm_64
redhat enterprise_linux_for_arm_64_els
redhat enterprise_linux_for_arm_64_eus
redhat enterprise_linux_for_els
redhat enterprise_linux_for_eus
redhat enterprise_linux_for_ibm_z_systems
redhat enterprise_linux_for_ibm_z_systems_els
redhat enterprise_linux_for_ibm_z_systems_eus
redhat enterprise_linux_for_power_little_endian_els
redhat enterprise_linux_for_power_little_endian_eus
redhat enterprise_linux_for_update_services_for_sap_solutions
redhat enterprise_linux_server_aus
redhat enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
redhat openshift_logging · 5.0 → 5.8.6

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References