6.7

CVE-2024-0193

Kernel: netfilter: use-after-free in nft_trans_gc_catchall_sync leads to privilege escalation

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user with CAP_NET_ADMIN capability to escalate their privileges on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Codeready Linux Builder For Eus Version 9.2 HwPlatform x64
Redhat ≫ Enterprise Linux Version 9.2 HwPlatform arm64
Redhat ≫ Enterprise Linux For Els Version 9.2 HwPlatform arm64
Redhat ≫ Enterprise Linux For Els Version 9.2 HwPlatform x64
Redhat ≫ Enterprise Linux For Eus Version 9.2 HwPlatform arm64
Redhat ≫ Enterprise Linux For Eus Version 9.2 HwPlatform x64
Redhat ≫ Codeready Linux Builder Version 9.0 HwPlatform aarch64
Redhat ≫ Codeready Linux Builder For Eus Version 9.4 HwPlatform arm64
Redhat ≫ Codeready Linux Builder For Eus Version 9.4 HwPlatform x64
Redhat ≫ Codeready Linux Builder For Eus Version 9.6 HwPlatform arm64
Redhat ≫ Codeready Linux Builder For Eus Version 9.6 HwPlatform x64
Redhat ≫ Enterprise Linux Version 9.0 HwPlatform arm64
Redhat ≫ Enterprise Linux Version 9.0 HwPlatform x64
Redhat ≫ Enterprise Linux For Arm 64 Version 9.4_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Version 9.6_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Els Version 9.4_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Els Version 9.6_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 9.4_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 9.6_aarch64
Redhat ≫ Enterprise Linux For Els Version 9.4 HwPlatform x64
Redhat ≫ Enterprise Linux For Els Version 9.6 HwPlatform x64
Redhat ≫ Enterprise Linux For Eus Version 9.4 HwPlatform x64
Redhat ≫ Enterprise Linux For Eus Version 9.6 HwPlatform x64
Redhat ≫ Enterprise Linux For Arm 64 Version 9.0_aarch64
Linux ≫ Linux Kernel Version >= 5.10.198 < 5.10.206
Linux ≫ Linux Kernel Version >= 5.15.118 < 5.15.146
Linux ≫ Linux Kernel Version >= 6.1.35 < 6.1.71
Linux ≫ Linux Kernel Version >= 6.3.9 < 6.6.10
Redhat ≫ Openshift Logging Version >= 5.0 < 5.8.6
   Redhat ≫ Enterprise Linux Version 9.0
   Redhat ≫ Enterprise Linux Version 9.0 HwPlatform arm64
   Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.0
   Redhat ≫ Enterprise Linux For Power Little Endian Version 9.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.84% 0.535
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
RedHat 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://access.redhat.com/errata/RHSA-2024:2094
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1248
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1018
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1019
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:4412
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:4415
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2024-0193
Third Party Advisory
Mitigation
https://bugzilla.redhat.com/show_bug.cgi?id=2255653
Patch
Third Party Advisory
Issue Tracking