PT-2024-29726 · Linux+10 · Linux Kernel+10

Linus Torvalds

·

Published

2024-06-26

·

Updated

2025-09-29

·

CVE-2024-42070

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description The issue is related to the netfilter component of the Linux kernel, specifically with the nf tables subsystem. The problem arises from the conditional validation of NFT DATA VALUE when storing data in registers. Since the datatype is always either NFT DATA VALUE or NFT DATA VERDICT, a new helper function can infer the register type from the set datatype, allowing the removal of the conditional check. Without this fix, a pointer to a chain object can be leaked through the registers, potentially leading to information disclosure. This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Type Confusion

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8856
ALSA-2024:8870
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-10855
ALT-PU-2024-11524
ALT-PU-2024-12537
ALT-PU-2024-13979
ALT-PU-2024-14046
ALT-PU-2024-9967
AZL-47154
BDU:2025-02535
CESA-2024_8856
CESA-2024_8870
CVE-2024-42070
DLA-4008-1
INFSA-2024_8856
INFSA-2024_8870
INFSA-2024_9315
OESA-2024-2028
OESA-2024-2029
OESA-2024-2030
OESA-2024-2031
OESA-2024-2076
OPENSUSE-SU-2024_2947-1
RHSA-2024:8856
RHSA-2024:8870
RHSA-2024:9315
RHSA-2024_8856
RHSA-2024_8870
RHSA-2024_9315
RHSA-2025:4342
RLSA-2024:8856
RLSA-2024:8870
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7003-1
USN-7003-2
USN-7003-3
USN-7003-4
USN-7003-5
USN-7006-1
USN-7007-1
USN-7007-2
USN-7007-3
USN-7009-1
USN-7009-2
USN-7019-1
USN-7089-1
USN-7089-2
USN-7089-3
USN-7089-4
USN-7089-5
USN-7089-6
USN-7089-7
USN-7090-1
USN-7095-1
USN-7156-1
USN-7332-1
USN-7332-2
USN-7332-3
USN-7342-1
USN-7344-1
USN-7344-2
ZDI-24-1642

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linux Kernel
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu