UBUNTU-CVE-2024-1086
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-1086
UBUNTU-CVE-2024-1086
Summary:
Details: A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.
References: https://ubuntu.com/security/CVE-2024-1086, https://kernel.dance/f342de4e2f33e0e39165d8639387aa6c19dff660, https://git.kernel.org/linus/f342de4e2f33e0e39165d8639387aa6c19dff660, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f342de4e2f33e0e39165d8639387aa6c19dff660, https://ubuntu.com/security/notices/USN-6688-1, https://ubuntu.com/security/notices/USN-6700-1, https://ubuntu.com/security/notices/USN-6701-1, https://ubuntu.com/security/notices/USN-6702-1, https://ubuntu.com/security/notices/USN-6704-1, https://ubuntu.com/security/notices/USN-6705-1, https://ubuntu.com/security/notices/USN-6707-1, https://ubuntu.com/security/notices/USN-6701-2, https://ubuntu.com/security/notices/USN-6702-2, https://ubuntu.com/security/notices/USN-6704-2, https://ubuntu.com/security/notices/USN-6707-2, https://ubuntu.com/security/notices/USN-6700-2, https://ubuntu.com/security/notices/USN-6701-3, https://ubuntu.com/security/notices/USN-6704-3, https://ubuntu.com/security/notices/USN-6707-3, https://ubuntu.com/security/notices/USN-6716-1, https://ubuntu.com/security/notices/USN-6704-4, https://ubuntu.com/security/notices/USN-6707-4, https://ubuntu.com/security/notices/USN-6701-4, https://www.cve.org/CVERecord?id=CVE-2024-1086, https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
