PT-2024-1933 · Linux+8 · Linux Kernel+8

Published

2024-02-08

·

Updated

2026-03-27

·

CVE-2024-26581

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the netfilter component of the Linux kernel, specifically the nft set rbtree function. It involves an out-of-bounds write vulnerability that could allow a remote attacker to execute arbitrary code. The vulnerability is associated with a use-after-free condition in the nftables subsystem of the Linux kernel. There is a publicly disclosed proof-of-concept exploit that poses a significant threat to Linux systems, potentially allowing unauthorized access to root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Use After Free

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5928
ALSA-2025_16880
ALT-PU-2024-14046
ALT-PU-2024-3457
ALT-PU-2024-6818
AZL-35451
AZL-35475
BDU:2024-01724
CVE-2024-26581
DLA-3842-1
DSA-5658-1
DSA-5681-1
INFSA-2024_5928
LSN-0104-1
OPENSUSE-SU-2024_2185-1
RHSA-2024:4823
RHSA-2024:4831
RHSA-2024:5928
RHSA-2024_5928
SUSE-SU-2024:2010-1
SUSE-SU-2024:2183-1
SUSE-SU-2024:2185-1
SUSE-SU-2026:0474-1
SUSE-SU-2026:0496-1
SUSE-SU-2026:0617-1
SUSE-SU-2026:1131-1
USN-6688-1
USN-6741-1
USN-6742-1
USN-6742-2
USN-6743-1
USN-6743-2
USN-6743-3

Affected Products

Alt Linux
Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu