PT-2024-1597 · Linux+10 · Linux Kernel+10

Notselwyn

·

Publicado

2024-01-24

·

Atualizado

2026-05-29

·

CVE-2024-1086

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Nome do software vulnerável e versões afetadas:
versões do kernel anteriores à 6.1.77-alt1
versões do kernel-uek, kernel-uek-debug, kernel-uek-debug-devel, kernel-uek-devel, kernel-uek-doc e kernel-uek-tools anteriores à 6.1.77-alt1
versões do kernel 5.10.206 a 5.10.209 (Debian 10 buster)
versão do kernel 4.12.14-122 186
Descrição:
Várias vulnerabilidades foram descobertas em diversos pacotes do kernel Linux, incluindo bpftool, kernel, kernel-abi-whitelists, kernel-debug, kernel-debug-devel, kernel-devel, kernel-doc, kernel-headers, kernel-tools, kernel-tools-libs, kernel-tools-libs-devel, perf e python-perf. Essas vulnerabilidades podem levar à escalada de privilégios, negação de serviço ou vazamento de informações. Especificamente, existe uma vulnerabilidade do tipo “use-after-free” no componente nf tables do kernel versão 4.12.14-122 186, que poderia ser explorada para obter escalada de privilégios local.
Recomendações:
Atualize para a versão 6.1.77-alt1 do kernel ou posterior.
Atualize o kernel-uek, kernel-uek-debug, kernel-uek-debug-devel, kernel-uek-devel, kernel-uek-doc e kernel-uek-tools para a versão 6.1.77-alt1 ou posterior.
Para o Debian 10 buster, atualize para a versão 5.10.209-2~deb10u1 do kernel ou posterior.
Para a versão 4.12.14-122 186 do kernel, aplique a atualização disponível para corrigir a vulnerabilidade de uso após liberação de memória.

Exploit

Correção

LPE

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2024:1607
ALSA-2024:2394
ALSA-2024_10939
ALSA-2024_11486
ALSA-2024_1607
ALSA-2024_2394
ALSA-2025_11850
ALSA-2025_11851
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALSA-2025_18281
ALSA-2025_19102
ALSA-2025_19103
ALSA-2025_19409
ALSA-2025_22387
ALSA-2025_22388
ALSA-2025_22800
ALSA-2025_22801
ALSA-2025_2627
ALT-PU-2024-1865
ALT-PU-2024-1921
ALT-PU-2024-1930
ALT-PU-2024-2015
ALT-PU-2024-4263
ALT-PU-2024-4843
AZL-34155
AZL-34874
BDU:2024-01187
CESA-2024_1249
CESA-2024_1607
CESA-2024_1614
CVE-2024-1086
DLA-3840-1
DLA-3841-1
ELSA-2024-12255
ELSA-2024-12256
ELSA-2024-12257
ELSA-2024-12258
ELSA-2024-12259
ELSA-2024-12260
ELSA-2024-12265
ELSA-2024-12266
ELSA-2024-12270
ELSA-2024-12271
ELSA-2024-12274
ELSA-2024-12275
ELSA-2024-12378
ELSA-2024-1249
ELSA-2024-1607
ELSA-2024-2394
INFSA-2024_2394
LSN-0102-1
LSN-0103-1
OESA-2024-1175
OESA-2024-1176
OESA-2024-1177
OESA-2024-1178
OESA-2024-1179
OESA-2024-1180
OPENSUSE-SU-2024_0469-1
OPENSUSE-SU-2024_0515-1
RHSA-2024:0930
RHSA-2024:1018
RHSA-2024:1019
RHSA-2024:1249
RHSA-2024:1332
RHSA-2024:1404
RHSA-2024:1607
RHSA-2024:1614
RHSA-2024:2394
RHSA-2024:2697
RHSA-2024:3318
RHSA-2024:3319
RHSA-2024:3414
RHSA-2024:3421
RHSA-2024:3427
RHSA-2024:3528
RHSA-2024:3529
RHSA-2024:3530
RHSA-2024:3805
RHSA-2024:4073
RHSA-2024:4074
RHSA-2024:4075
RHSA-2024_1249
RHSA-2024_1332
RHSA-2024_1607
RHSA-2024_1614
RHSA-2024_2394
RLSA-2024:1607
RLSA-2024:1614
RLSA-2024_1607
RLSA-2024_1614
RXSA-2024:1607
SUSE-SU-2024:0463-1
SUSE-SU-2024:0468-1
SUSE-SU-2024:0469-1
SUSE-SU-2024:0474-1
SUSE-SU-2024:0476-1
SUSE-SU-2024:0478-1
SUSE-SU-2024:0483-1
SUSE-SU-2024:0484-1
SUSE-SU-2024:0514-1
SUSE-SU-2024:0515-1
SUSE-SU-2024:0516-1
SUSE-SU-2024:1358-1
SUSE-SU-2024:1359-1
SUSE-SU-2024:1364-1
SUSE-SU-2024:1373-1
SUSE-SU-2024:1380-1
SUSE-SU-2024:1382-1
SUSE-SU-2024:1386-1
SUSE-SU-2024:1388-1
SUSE-SU-2024:1390-1
SUSE-SU-2024:1400-1
SUSE-SU-2024:1401-1
SUSE-SU-2024:1405-1
SUSE-SU-2024:1406-1
SUSE-SU-2024:1410-1
SUSE-SU-2024:1418-1
SUSE-SU-2024:1493-1
SUSE-SU-2024:1505-1
SUSE-SU-2024:1506-1
SUSE-SU-2024:1537-1
SUSE-SU-2024:1545-1
SUSE-SU-2024:1551-1
SUSE-SU-2024:1554-1
SUSE-SU-2024:1558-1
SUSE-SU-2024:1562-1
SUSE-SU-2024:1580-1
SUSE-SU-2024:1581-1
SUSE-SU-2024:1582-1
SUSE-SU-2024:1596-1
SUSE-SU-2024_0468-1
SUSE-SU-2024_0469-1
SUSE-SU-2024_0474-1
SUSE-SU-2024_0478-1
SUSE-SU-2024_0483-1
SUSE-SU-2024_0484-1
SUSE-SU-2024_0514-1
SUSE-SU-2024_0515-1
SUSE-SU-2024_0516-1
USN-6688-1
USN-6700-1
USN-6700-2
USN-6701-1
USN-6701-2
USN-6701-3
USN-6701-4
USN-6702-1
USN-6702-2
USN-6704-1
USN-6704-2
USN-6704-3
USN-6704-4
USN-6705-1
USN-6707-1
USN-6707-2
USN-6707-3
USN-6707-4
USN-6716-1

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu