PT-2024-1933 · Linux+8 · Linux Kernel+8
Published
2024-02-08
·
Updated
2026-03-27
·
CVE-2024-26581
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the netfilter component of the Linux kernel, specifically the nft set rbtree function. It involves an out-of-bounds write vulnerability that could allow a remote attacker to execute arbitrary code. The vulnerability is associated with a use-after-free condition in the nftables subsystem of the Linux kernel. There is a publicly disclosed proof-of-concept exploit that poses a significant threat to Linux systems, potentially allowing unauthorized access to root privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Buffer Overflow
Use After Free
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu