CVE-2024-1086
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT.
We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
Affected (16)
Products: Linux: Linux Kernel · Fedoraproject: Fedora · Redhat: Enterprise Linux Desktop, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Power Big Endian, Enterprise Linux For Power Little Endian, Enterprise Linux Server, Enterprise Linux Workstation · +2 more
Show all products
Linux: Linux Kernel · Fedoraproject: Fedora · Redhat: Enterprise Linux Desktop, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Power Big Endian, Enterprise Linux For Power Little Endian, Enterprise Linux Server, Enterprise Linux Workstation · Debian: Debian Linux · Netapp: A250 Firmware, 500f Firmware, C250 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.15 to 5.15.149 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 39 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 | |
| Version 7.0_s390x | |
| Version 7.0_ppc64 | |
| Version 7.0_ppc64le | |
| Version 7.0 | |
| Version 7.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp A250 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp 500f | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp C250 | All versions |
References (29)
Source: cve-coordination@google.com
Mailing ListPatch
Source: cve-coordination@google.com
Mailing ListPatch
Source: cve-coordination@google.com
ExploitMailing List
Source: cve-coordination@google.com
Mailing List
Source: cve-coordination@google.com
ExploitMailing List
Source: cve-coordination@google.com
Patch
Source: cve-coordination@google.com
ExploitThird Party Advisory
Source: cve-coordination@google.com
Patch
Source: cve-coordination@google.com
Mailing List
Source: cve-coordination@google.com
Mailing List
Source: cve-coordination@google.com
Mailing List
Source: cve-coordination@google.com
ExploitTechnical DescriptionThird Party Advisory
Source: cve-coordination@google.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.