PT-2024-37512 · Google · Nftables

Bughunter2

·

Published

2024-07-03

·

Updated

2025-09-08

·

CVE-2024-6284

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: github.com/google/nftables version 0.1.0
Description: The issue arises from IP addresses being encoded in the wrong byte order, resulting in an nftables configuration that does not work as intended. This could lead to either blocking or not blocking the desired addresses.
Recommendations: For github.com/google/nftables version 0.1.0, update to version 0.2.0 to resolve the issue.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-6284
GHSA-QJVF-8748-9W7H
GO-2024-2977

Affected Products

Nftables