PT-2023-8117 · Linux+4 · Linux Kernel+4
Mauro Matteo Cascella
·
Publicado
2023-12-20
·
Atualizado
2026-06-05
·
CVE-2024-0193
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux Kernel (affected versions not specified)
Description
A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT CHAIN object or NFT OBJECT object, allowing a local unprivileged user with CAP NET ADMIN capability to escalate their privileges on the system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel
Linuxmint
Red Hat
Red Os
Ubuntu